Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-19558 | Mattermost Incorrect Authorization vulnerability |
Github GHSA |
GHSA-wgvp-jj4w-88hf | Mattermost Incorrect Authorization vulnerability |
Solution
Update Mattermost to versions 10.9.0, 10.5.6, 9.11.16, 10.8.1, 10.7.3, 10.6.6 or higher.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
Tue, 08 Jul 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost
Mattermost mattermost Server |
|
| CPEs | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* cpe:2.3:a:mattermost:mattermost_server:10.8.0:-:*:*:*:*:*:* cpe:2.3:a:mattermost:mattermost_server:10.8.0:rc1:*:*:*:*:*:* cpe:2.3:a:mattermost:mattermost_server:10.8.0:rc2:*:*:*:*:*:* cpe:2.3:a:mattermost:mattermost_server:10.8.0:rc3:*:*:*:*:*:* |
|
| Vendors & Products |
Mattermost
Mattermost mattermost Server |
Mon, 30 Jun 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 30 Jun 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly validate channel membership when retrieving playbook run metadata, allowing authenticated users who are playbook members but not channel members to access sensitive information about linked private channels including channel name, display name, and participant count through the run metadata API endpoint. | |
| Title | Mattermost Playbooks exposes private channel metadata to unauthorized users via run metadata API | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2025-06-30T20:48:41.938Z
Reserved: 2025-05-23T09:42:12.046Z
Link: CVE-2025-47871
Updated: 2025-06-30T20:48:39.016Z
Status : Analyzed
Published: 2025-06-30T17:15:32.777
Modified: 2025-07-08T14:11:33.783
Link: CVE-2025-47871
No data.
OpenCVE Enrichment
Updated: 2025-07-06T22:16:25Z
EUVD
Github GHSA