CVE-2025-20630: Mobile crash via object that can't be cast to String in Attachment Field
Published Jan 16, 2025
·Updated
Mattermost Mobile versions <=2.22.0 fail to properly handle posts with attachments containing fields that cannot be cast to a String, which allows an attacker to cause the mobile to crash via creating and sending such a post to a channel.
Affected Software
2 affected components
Mattermost Mattermost Mobile<=2.22.0
Mattermost Mattermost Mobile<2.23.0
Remediation
Information
Update Mattermost Mobile to version 2.23.0 or higher.
Event History
Jan 16, 2025
CVE Published
via MITRE·06:18 PM
Data Sourced
via MITRE·06:18 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-20630?
CVE-2025-20630 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2025-20630?
To fix CVE-2025-20630, update to Mattermost Mobile version 2.22.1 or later.
3
What impact does CVE-2025-20630 have on Mattermost Mobile?
CVE-2025-20630 allows an attacker to crash the mobile app by sending a malicious post with non-string fields.
4
Which versions of Mattermost Mobile are affected by CVE-2025-20630?
Mattermost Mobile versions 2.22.0 and earlier are affected by CVE-2025-20630.
5
Is there a workaround for CVE-2025-20630?
There is no known workaround for CVE-2025-20630; updating to a secure version is required.