Mattermost versions 9.11.x <= 9.11.8 fail to properly perform authorization of the Viewer role which allows an attacker with the Viewer role configured with No Access to Reporting to still view team and site statistics.
References
Link | Resource |
---|---|
https://mattermost.com/security-updates |
Configurations
No configuration.
History
19 Mar 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-03-19 15:15
Updated : 2025-03-19 15:15
NVD link : CVE-2025-1472
Mitre link : CVE-2025-1472
CVE.ORG link : CVE-2025-1472
JSON object : View
Products Affected
No product.
CWE
CWE-863
Incorrect Authorization