No analysis available yet.
Vendor Solution
Update Mattermost to versions 10.5.0, 10.1.4, 10.4.2, 9.11.8, 10.3.3, 10.2.3 or higher. Alternatively, update the channel export plugin to v1.2.1.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-4307 | Mattermost versions 10.1.x <= 10.1.3, 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to restrict channel export of archived channels when the "Allow users to view archived channels" is disabled which allows a user to export channel contents when they shouldn't have access to it |
Github GHSA |
GHSA-q8p2-2hwc-jw64 | Mattermost fails to restrict channel export of archived channels |
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
Wed, 01 Oct 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost mattermost Server
|
|
| CPEs | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mattermost mattermost Server
|
Mon, 24 Feb 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 24 Feb 2025 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mattermost versions 10.1.x <= 10.1.3, 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to restrict channel export of archived channels when the "Allow users to view archived channels" is disabled which allows a user to export channel contents when they shouldn't have access to it | |
| Title | Channel export permitted on archived channel when viewing archived channels is disabled | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2025-02-24T11:24:41.215Z
Reserved: 2025-02-18T11:11:14.648Z
Link: CVE-2025-24526
Updated: 2025-02-24T11:24:33.790Z
Status : Analyzed
Published: 2025-02-24T08:15:10.427
Modified: 2025-10-01T18:03:20.600
Link: CVE-2025-24526
No data.
OpenCVE Enrichment
Updated: 2025-07-13T11:07:11Z
EUVD
Github GHSA