Security Flaw in Mattermost Leads to Unauthorized Metadata Exposure
CVE-2025-2424
3.1LOW
What is CVE-2025-2424?
A security flaw in Mattermost versions 10.5.0 through 10.5.1 and 9.11.8 through 9.11.9 allows an attacker to exploit the system by creating bookmarks referencing deleted files. This vulnerability arises from the lack of checks to confirm if a file has been properly deleted. As a result, attackers who possess the IDs of these files can access their associated metadata, potentially leading to exposure of sensitive information.
Affected Version(s)
Mattermost 10.5.0 <= 10.5.1
Mattermost 9.11.0 <= 9.11.9
Mattermost 10.6.0