CVE-2024-39767

Source
https://cve.org/CVERecord?id=CVE-2024-39767
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-39767.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-39767
Published
2024-07-15T09:15:02.573Z
Modified
2026-03-14T12:34:51.256223Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

Mattermost Mobile Apps versions <=2.16.0 fail to validate that the push notifications received for a server actually came from this serve that which allows a malicious server to send push notifications with another server’s diagnostic ID or server URL and have them show up in mobile apps as that server’s push notifications.

References

Affected packages

Git / github.com/mattermost/mattermost-mobile

Affected ranges

Type
GIT
Repo
https://github.com/mattermost/mattermost-mobile
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2.17.0"
        }
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-39767.json"