First published: Wed Jan 15 2025(Updated: )
Mattermost Mobile Apps versions <=2.22.0 fail to properly validate post props which allows a malicious authenticated user to cause a crash via a malicious post.
Credit: responsibledisclosure@mattermost.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mattermost Mobile Apps | <=2.22.0 |
Update Mattermost Mobile Apps to versions 2.23.0 or higher.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2025-21083 is classified as moderate due to the potential for app crashes caused by malicious posts.
To fix CVE-2025-21083, upgrade to Mattermost Mobile Apps version 2.22.1 or later.
CVE-2025-21083 affects users of Mattermost Mobile Apps versions up to and including 2.22.0.
CVE-2025-21083 enables authenticated users to crash the mobile app by sending a malicious post.
CVE-2025-21083 is considered a local vulnerability as it requires authenticated access to the Mattermost Mobile Apps.