Mattermost Improper Validation of Specified Type of Input vulnerability
Moderate severity
GitHub Reviewed
Published
Jan 9, 2025
to the GitHub Advisory Database
•
Updated Jan 9, 2025
Package
Affected versions
>= 9.11.0, < 9.11.16
>= 10.0.0, < 10.0.4
>= 10.1.0, < 10.1.4
= 10.2.0
< 8.0.0-20250102081831-64c566a8280b
Patched versions
9.11.16
10.0.4
10.1.4
10.2.1
8.0.0-20250102081831-64c566a8280b
Description
Published by the National Vulnerability Database
Jan 9, 2025
Published to the GitHub Advisory Database
Jan 9, 2025
Reviewed
Jan 9, 2025
Last updated
Jan 9, 2025
Mattermost versions 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate post types, which allows attackers to deny service to users with the sysconsole_read_plugins permission via creating a post with the custom_pl_notification type and specific props.
References