Authorization Flaw in Mattermost Affects Viewer Role Permissions
CVE-2025-1472
4.3MEDIUM
What is CVE-2025-1472?
Mattermost versions 9.11.x through 9.11.8 exhibit an authorization flaw affecting the Viewer role, improperly allowing users configured with No Access to Reporting to view sensitive team and site statistics. This vulnerability could potentially expose confidential information to unauthorized individuals, posing a risk to data privacy and integrity.
Affected Version(s)
Mattermost 9.11.0 <= 9.11.8
Mattermost 10.5.0
Mattermost 9.11.9