CVE-2024-24975

Source
https://cve.org/CVERecord?id=CVE-2024-24975
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-24975.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-24975
Published
2024-03-15T09:07:13.379Z
Modified
2026-08-12T03:51:42.104999038Z
Severity
  • 3.5 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L CVSS Calculator
Summary
Denial of Service for mobile app users due to automatic code highlighting
Details

Uncontrolled Resource Consumption in Mattermost Mobile versions before 2.13.0 fails to limit the size of the code block that will be processed by the syntax highlighter, allowing an attacker to send a very large code block and crash the mobile app.

Database specific
{
    "cwe_ids": [
        "CWE-400"
    ],
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "last_affected": "2.12.0"
                }
            ]
        },
        {
            "source": "DESCRIPTION",
            "extracted_events": [
                {
                    "fixed": "2.13.0"
                }
            ]
        }
    ],
    "cna_assigner": "Mattermost",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/24xxx/CVE-2024-24975.json"
}
References

Affected packages

Git / github.com/mattermost/mattermost-mobile

Affected ranges

Type
GIT
Repo
https://github.com/mattermost/mattermost-mobile
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "cpe": "cpe:2.3:a:mattermost:mattermost_mobile:*:*:*:*:*:*:*:*",
    "source": "CPE_RANGE",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2.13.0"
        }
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-24975.json"