We found results for “”
CVE-2025-1792
Good to know:
Date: May 30, 2025
Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to properly enforce access controls for guest users accessing channel member information, allowing authenticated guest users to view metadata about members of public channels via the channel members API endpoint.
Severity Score
Related Resources (6)
Severity Score
Weakness Type (CWE)
Incorrect Authorization
CWE-863Top Fix
Upgrade Version
Upgrade to version github.com/mattermost/mattermost/server/v8 - v8.0.0-20250414110750-c23f44fe8ed0;github.com/mattermost/mattermost-server - v9.11.13+incompatible;https://github.com/mattermost/mattermost.git - v10.7.1;https://github.com/mattermost/mattermost.git - v10.5.4;https://github.com/mattermost/mattermost.git - v9.11.13
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | HIGH |
| Privileges Required (PR): | LOW |
| User Interaction (UI): | NONE |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | LOW |
| Integrity (I): | NONE |
| Availability (A): | NONE |
Vulnerabilities
Projects
Contact Us


