Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-16491 | Mattermost fails to properly invalidate personal access tokens upon user deactivation |
Github GHSA |
GHSA-mc2f-jgj6-6cp3 | Mattermost fails to properly invalidate personal access tokens upon user deactivation |
Solution
Update Mattermost to versions 10.8.0, 10.7.1, 10.6.3, 10.5.4, 9.11.13 or higher.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
Wed, 15 Oct 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost mattermost Server
|
|
| CPEs | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mattermost mattermost Server
|
Fri, 30 May 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 30 May 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly invalidate personal access tokens upon user deactivation, allowing deactivated users to maintain full system access by exploiting access token validation flaws via continued usage of previously issued tokens. | |
| Title | Bypass of System Admin User Deactivation Controls for Personal Access Tokens in Mattermost Server | |
| Weaknesses | CWE-303 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2025-05-30T14:42:40.557Z
Reserved: 2025-04-03T15:46:34.595Z
Link: CVE-2025-3230
Updated: 2025-05-30T14:42:31.645Z
Status : Analyzed
Published: 2025-05-30T15:15:41.043
Modified: 2025-10-15T14:16:49.363
Link: CVE-2025-3230
No data.
OpenCVE Enrichment
Updated: 2025-06-24T09:44:21Z
EUVD
Github GHSA