Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-8j3q-gc9x-7972: Mattermost Incorrect Type Conversion or Cast

Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate the style of proto supplied to an action’s style in post.props.attachments, which allows an attacker to crash the frontend via crafted malicious input.

ghsa
#git#perl
  1. GitHub Advisory Database
  2. GitHub Reviewed
  3. CVE-2025-21088

Mattermost Incorrect Type Conversion or Cast

Moderate severity GitHub Reviewed Published Jan 15, 2025 to the GitHub Advisory Database • Updated Jan 15, 2025

Package

gomod github.com/mattermost/mattermost/server/v8 (Go)

Affected versions

>= 10.2.0, < 10.2.1

>= 10.1.0, <= 10.1.3

>= 10.0.0, <= 10.0.3

>= 9.11.0, <= 9.11.5

< 8.0.0-20241127161322-25ff7a3779a5

Patched versions

10.2.1

10.1.4

10.0.4

9.11.6

8.0.0-20241127161322-25ff7a3779a5

Published to the GitHub Advisory Database

Jan 15, 2025

Last updated

Jan 15, 2025

ghsa: Latest News

GHSA-c873-wfhp-wx5m: SP1 has missing verifier checks and fiat-shamir observations