CVE-2025-20621
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Jan 16, 2025
CWE ID 1287
Summary
CVE-2025-20621 is a vulnerability affecting Mattermost versions 10.2.x up to 10.2.0, 9.11.x up to 9.11.5, 10.0.x up to 10.0.3, and 10.1.x up to 10.1.3. This issue arises due to the webapp's inability to handle posts with attachments containing fields that cannot be cast to a String. An attacker can exploit this flaw by crafting and sending such a malicious post to a channel, leading to a webapp crash. This vulnerability poses a risk to the availability and integrity of Mattermost instances, necessitating immediate updates to affected versions.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Mattermost Server
Affected Vendors
- Mattermost, Inc.