4.9
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Description
Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.10.x <= 10.10.0, 10.9.x <= 10.9.3 fail to validate import data which allows a system admin to crash the server via the bulk import feature.
Basic Information
ID
CVE-2025-8402
Source
Mattermost
Published
Aug 21, 2025 at 17:01
Modified
Aug 21, 2025 at 17:30
Affected Product
Vendor
Mattermost
Product
Mattermost
Version
10.8.0
Affected Versions
Mattermost Mattermost 10.8.0
Mattermost Mattermost 10.5.0
Mattermost Mattermost 9.11.0
Mattermost Mattermost 10.10.0
Mattermost Mattermost 10.9.0
Mattermost Mattermost 10.5.0
Mattermost Mattermost 9.11.0
Mattermost Mattermost 10.10.0
Mattermost Mattermost 10.9.0