Mattermost webapp crash via a crafted post
Moderate severity
GitHub Reviewed
Published
Jan 16, 2025
to the GitHub Advisory Database
•
Updated Jan 16, 2025
Package
Affected versions
>= 10.2.0, < 10.2.1
>= 10.1.0, <= 10.1.3
>= 10.0.0, <= 10.0.3
>= 9.11.0, <= 9.11.5
< 8.0.0-20241127161322-25ff7a3779a5
Patched versions
10.2.1
10.1.4
10.0.4
9.11.6
8.0.0-20241127161322-25ff7a3779a5
Description
Published by the National Vulnerability Database
Jan 16, 2025
Published to the GitHub Advisory Database
Jan 16, 2025
Reviewed
Jan 16, 2025
Last updated
Jan 16, 2025
Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly handle posts with attachments containing fields that cannot be cast to a String, which allows an attacker to cause the webapp to crash via creating and sending such a post to a channel.
References