Mattermost versions 9.11.x <= 9.11.6 fail to filter out DMs from the deleted channels endpoint which allows an attacker to infer user IDs and other metadata from deleted DMs if someone had manually marked DMs as deleted in the database.
References
Link | Resource |
---|---|
https://mattermost.com/security-updates | Vendor Advisory |
Configurations
History
29 Sep 2025, 18:11
Type | Values Removed | Values Added |
---|---|---|
First Time |
Mattermost mattermost Server
Mattermost |
|
References | () https://mattermost.com/security-updates - Vendor Advisory | |
Summary |
|
|
CPE | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* |
14 Feb 2025, 18:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-02-14 18:15
Updated : 2025-09-29 18:11
NVD link : CVE-2025-0503
Mitre link : CVE-2025-0503
CVE.ORG link : CVE-2025-0503
JSON object : View
Products Affected
mattermost
- mattermost_server
CWE
CWE-754
Improper Check for Unusual or Exceptional Conditions