Data Exposure in Mattermost by Allowing Access to Deleted Messages
CVE-2025-0503
3.1LOW
Summary
Versions of Mattermost from 9.11.x up to 9.11.6 contain a vulnerability that allows an unauthorized user to access metadata, including user IDs, from deleted direct messages via the deleted channels endpoint. This flaw stems from insufficient filtering of data, creating a potential avenue for attackers to infer sensitive information about users who used the platform. Users are advised to upgrade to the latest version to mitigate this risk.
Affected Version(s)
Mattermost 9.11.0 <= 9.11.6
Mattermost 10.4.0
Mattermost 9.11.7
References
CVSS V3.1
Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Devin Binnie