First published: Fri Dec 17 2021(Updated: )
Mattermost 6.0 and earlier fails to sufficiently validate parameters during post creation, which allows authenticated attackers to cause a client-side crash of the web application via a maliciously crafted post.
Credit: responsibledisclosure@mattermost.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mattermost Mattermost Server | <=6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-37863 is a vulnerability in Mattermost 6.0 and earlier versions that allows authenticated attackers to cause a client-side crash of the web application by creating a malicious post.
CVE-2021-37863 has a severity score of 5.7, which is considered medium.
CVE-2021-37863 impacts Mattermost Server versions up to and including 6.0.
An attacker with CVE-2021-37863 can cause a client-side crash of the Mattermost web application.
Yes, you can find references for CVE-2021-37863 at the following URLs: https://hackerone.com/reports/1253732, https://mattermost.com/security-updates/