Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-16492 | Mattermost fails to properly enforce access control restrictions for System Manager roles |
Github GHSA |
GHSA-86jg-35xj-3vv5 | Mattermost fails to properly enforce access control restrictions for System Manager roles |
Solution
Update Mattermost to versions 10.8.0, 10.7.1, 10.5.4, 9.11.13 or higher.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
Tue, 08 Jul 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost
Mattermost mattermost Server |
|
| CPEs | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* cpe:2.3:a:mattermost:mattermost_server:10.7.0:-:*:*:*:*:*:* cpe:2.3:a:mattermost:mattermost_server:10.7.0:rc1:*:*:*:*:*:* cpe:2.3:a:mattermost:mattermost_server:10.7.0:rc2:*:*:*:*:*:* |
|
| Vendors & Products |
Mattermost
Mattermost mattermost Server |
Fri, 30 May 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 30 May 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly enforce access control restrictions for System Manager roles, allowing authenticated users with System Manager privileges to view team details they should not have access to via direct API requests to team endpoints, even when explicitly configured with 'No access' to Teams in the System Console. | |
| Title | Improper Access Control in Mattermost allows System Managers to view team details despite role restrictions | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2025-05-30T14:37:42.109Z
Reserved: 2025-04-14T20:40:50.972Z
Link: CVE-2025-3611
Updated: 2025-05-30T14:37:32.312Z
Status : Analyzed
Published: 2025-05-30T15:15:41.197
Modified: 2025-07-08T17:11:34.797
Link: CVE-2025-3611
No data.
OpenCVE Enrichment
Updated: 2025-06-24T09:44:20Z
EUVD
Github GHSA