CVE-2025-21088

Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate the style of proto supplied to an action's style in post.props.attachments, which allows an attacker to crash the frontend via crafted malicious input.
References
Configurations

No configuration.

History

15 Jan 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-15 16:15

Updated : 2025-01-15 16:15


NVD link : CVE-2025-21088

Mitre link : CVE-2025-21088

CVE.ORG link : CVE-2025-21088


JSON object : View

Products Affected

No product.

CWE
CWE-704

Incorrect Type Conversion or Cast