Description

Mattermost Mobile Apps versions <=2.16.0 fail to validate that the push notifications received for a server actually came from this serve that which allows a malicious server to send push notifications with another server’s diagnostic ID or server URL and have them show up in mobile apps as that server’s push notifications.

INFO

Published Date :

2024-07-15T08:43:10.236Z

Last Modified :

2024-08-02T04:26:15.989Z

Source :

Mattermost
AFFECTED PRODUCTS

The following products are affected by CVE-2024-39767 vulnerability.

Vendors Products
Mattermost
  • Mattermost Mobile
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2024-39767.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact