VYPR
Moderate severityNVD Advisory· Published Jan 15, 2025· Updated Jan 15, 2025

WebApp crash via improper validation of proto style in attachments

CVE-2025-21088

Description

Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate the style of proto supplied to an action's style in post.props.attachments, which allows an attacker to crash the frontend via crafted malicious input.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/mattermost/mattermost/server/v8Go
>= 10.2.0, < 10.2.110.2.1
github.com/mattermost/mattermost/server/v8Go
>= 10.1.0, < 10.1.410.1.4
github.com/mattermost/mattermost/server/v8Go
>= 10.0.0, < 10.0.410.0.4
github.com/mattermost/mattermost/server/v8Go
>= 9.11.0, < 9.11.69.11.6
github.com/mattermost/mattermost/server/v8Go
< 8.0.0-20241127161322-25ff7a3779a58.0.0-20241127161322-25ff7a3779a5

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.