CVE-2025-21083: Insufficient Input Validation on Post Props
Published Jan 15, 2025
·Updated
Mattermost Mobile Apps versions <=2.22.0 fail to properly validate post props which allows a malicious authenticated user to cause a crash via a malicious post.
Affected Software
2 affected components
Mattermost Mattermost Mobile Apps<=2.22.0
Mattermost Mattermost Mobile<2.23.0
Remediation
Information
Update Mattermost Mobile Apps to versions 2.23.0 or higher.
Event History
Jan 15, 2025
CVE Published
via MITRE·04:10 PM
Data Sourced
via MITRE·04:10 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-21083?
The severity of CVE-2025-21083 is classified as moderate due to the potential for app crashes caused by malicious posts.
2
How do I fix CVE-2025-21083?
To fix CVE-2025-21083, upgrade to Mattermost Mobile Apps version 2.22.1 or later.
3
Who is affected by CVE-2025-21083?
CVE-2025-21083 affects users of Mattermost Mobile Apps versions up to and including 2.22.0.
4
What type of attack does CVE-2025-21083 enable?
CVE-2025-21083 enables authenticated users to crash the mobile app by sending a malicious post.
5
Is CVE-2025-21083 a remote or local vulnerability?
CVE-2025-21083 is considered a local vulnerability as it requires authenticated access to the Mattermost Mobile Apps.