Mattermost versions 9.11.x <= 9.11.8 fail to properly perform authorization of the Viewer role which allows an attacker with the Viewer role configured with No Access to Reporting to still view team and site statistics.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
Wed, 19 Mar 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 19 Mar 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mattermost versions 9.11.x <= 9.11.8 fail to properly perform authorization of the Viewer role which allows an attacker with the Viewer role configured with No Access to Reporting to still view team and site statistics. | |
| Title | Unauthorized View Access to Site Statistics and Team Statistics | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Mattermost
Published: 2025-03-19T14:11:03.977Z
Updated: 2025-03-19T14:40:59.930Z
Reserved: 2025-02-19T15:34:14.680Z
Link: CVE-2025-1472
Updated: 2025-03-19T14:39:59.425Z
Status : Received
Published: 2025-03-19T15:15:53.433
Modified: 2025-03-19T15:15:53.433
Link: CVE-2025-1472
No data.