Mattermost
cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*
- >= 10.2.0, <= 10.2.0
- >= 9.11.5, <= 9.11.5
- >= 10.0.3, <= 10.0.3
- >= 10.1.3, <= 10.1.3
A denial-of-service vulnerability has been identified in Mattermost versions 10.2.x through 10.2.0, 9.11.x through 9.11.5, 10.0.x through 10.0.3, and 10.1.x through 10.1.3. The issue arises because the application fails to properly process posts with attachments that include fields unable to be converted to a string. This flaw allows an attacker to crash the web application by creating and sending such a post to a channel.
Exploitation of this vulnerability leads to a crash of the Mattermost web application, causing a denial-of-service condition.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.