Mattermost Mobile app versions 2.13.0 and earlier use a regular expression with polynomial complexity to parse certain deeplinks, which allows an unauthenticated remote attacker to freeze or crash the app via a long maliciously crafted link.
Solution:
The product does not properly control the allocation and maintenance of a limited resource.
Link | Tags |
---|---|
https://mattermost.com/security-updates | vendor advisory |