Data Exposure in Mattermost by Allowing Access to Deleted Messages
CVE-2025-0503

3.1LOW

Key Information:

Vendor
Mattermost
Vendor
CVE Published:
14 February 2025

Summary

Versions of Mattermost from 9.11.x up to 9.11.6 contain a vulnerability that allows an unauthorized user to access metadata, including user IDs, from deleted direct messages via the deleted channels endpoint. This flaw stems from insufficient filtering of data, creating a potential avenue for attackers to infer sensitive information about users who used the platform. Users are advised to upgrade to the latest version to mitigate this risk.

Affected Version(s)

Mattermost 9.11.0 <= 9.11.6

Mattermost 10.4.0

Mattermost 9.11.7

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Devin Binnie
.