Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-w6xh-c82w-h997: Mattermost webapp crash via a crafted post

Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly handle posts with attachments containing fields that cannot be cast to a String, which allows an attacker to cause the webapp to crash via creating and sending such a post to a channel.

ghsa
#web#git#perl
  1. GitHub Advisory Database
  2. GitHub Reviewed
  3. CVE-2025-20621

Mattermost webapp crash via a crafted post

Moderate severity GitHub Reviewed Published Jan 16, 2025 to the GitHub Advisory Database • Updated Jan 16, 2025

Package

gomod github.com/mattermost/mattermost/server/v8 (Go)

Affected versions

>= 10.2.0, < 10.2.1

>= 10.1.0, <= 10.1.3

>= 10.0.0, <= 10.0.3

>= 9.11.0, <= 9.11.5

< 8.0.0-20241127161322-25ff7a3779a5

Patched versions

10.2.1

10.1.4

10.0.4

9.11.6

8.0.0-20241127161322-25ff7a3779a5

Published to the GitHub Advisory Database

Jan 16, 2025

Last updated

Jan 16, 2025

ghsa: Latest News

GHSA-4ff6-858j-r822: Gomatrixserverlib Server-Side Request Forgery (SSRF) on redirects and federation