CVE-2025-0503

Mattermost versions 9.11.x <= 9.11.6 fail to filter out DMs from the deleted channels endpoint which allows an attacker to infer user IDs and other metadata from deleted DMs if someone had manually marked DMs as deleted in the database.
References
Link Resource
https://mattermost.com/security-updates Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*

History

29 Sep 2025, 18:11

Type Values Removed Values Added
First Time Mattermost mattermost Server
Mattermost
References () https://mattermost.com/security-updates - () https://mattermost.com/security-updates - Vendor Advisory
Summary
  • (es) Las versiones 9.11.x &lt;= 9.11.6 de Mattermost no pueden filtrar los mensajes directos del endpoint de canales eliminados, lo que permite a un atacante inferir las identificaciones de usuario y otros metadatos de los mensajes directos eliminados si alguien había marcado manualmente los mensajes directos como eliminados en la base de datos.
CPE cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*

14 Feb 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-14 18:15

Updated : 2025-09-29 18:11


NVD link : CVE-2025-0503

Mitre link : CVE-2025-0503

CVE.ORG link : CVE-2025-0503


JSON object : View

Products Affected

mattermost

  • mattermost_server
CWE
CWE-754

Improper Check for Unusual or Exceptional Conditions