Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly invalidate personal access tokens upon user deactivation, allowing deactivated users to maintain full system access by exploiting access token validation flaws via continued usage of previously issued tokens.
References
Link | Resource |
---|---|
https://mattermost.com/security-updates |
Configurations
No configuration.
History
30 May 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-05-30 15:15
Updated : 2025-05-30 16:31
NVD link : CVE-2025-3230
Mitre link : CVE-2025-3230
CVE.ORG link : CVE-2025-3230
JSON object : View
Products Affected
No product.
CWE
CWE-303
Incorrect Implementation of Authentication Algorithm