Security Flaw in Mattermost Leads to Unauthorized Metadata Exposure
CVE-2025-2424
3.1LOW
Summary
A security flaw in Mattermost versions 10.5.0 through 10.5.1 and 9.11.8 through 9.11.9 allows an attacker to exploit the system by creating bookmarks referencing deleted files. This vulnerability arises from the lack of checks to confirm if a file has been properly deleted. As a result, attackers who possess the IDs of these files can access their associated metadata, potentially leading to exposure of sensitive information.
Affected Version(s)
Mattermost 10.5.0 <= 10.5.1
Mattermost 9.11.0 <= 9.11.9
Mattermost 10.6.0
References
CVSS V3.1
Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
vultza (vultza)