Impact
Mattermost Boards plugin fails to validate the type of fields.properties when a block is created. If an authenticated editor constructs a child block whose fields.properties is a non‑object value, the plugin worker crashes, raising a denial of service condition on the affected board. This flaw is a classic unvalidated input problem (CWE‑754) and allows an insider with editor rights to disrupt service without requiring any elevated privileges.
Affected Systems
Mattermost servers running affected releases are impacted, including 11.9.x releases up to and including 11.9.0, 11.8.4, 11.7.x releases up to and including 11.7.7, and 10.11.x releases up to and including 10.11.22. All other Mattermost versions receive the fix and are not vulnerable.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate impact. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting a lower likelihood of active exploitation. Nevertheless, the flaw is exploitable by any authenticated user with editor access, making it a practical risk for organizations that rely heavily on Mattermost Boards.
OpenCVE Enrichment