CVE-2025-2424

Mattermost versions 10.5.x <= 10.5.1, 9.11.x <= 9.11.9 fail to check if a file has been deleted when creating a bookmark which allows an attacker who knows the IDs of deleted files to obtain metadata of the files via bookmark creation.
References
Link Resource
https://mattermost.com/security-updates Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*

History

01 Oct 2025, 18:18

Type Values Removed Values Added
First Time Mattermost mattermost Server
Mattermost
CPE cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
References () https://mattermost.com/security-updates - () https://mattermost.com/security-updates - Vendor Advisory

15 Apr 2025, 18:39

Type Values Removed Values Added
Summary
  • (es) Las versiones 10.5.x &lt;= 10.5.1, 9.11.x &lt;= 9.11.9 de Mattermost no verifican si se ha eliminado un archivo al crear un marcador, lo que permite que un atacante que conoce los identificadores de los archivos eliminados obtenga metadatos de los archivos a través de la creación de un marcador.

14 Apr 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-14 15:15

Updated : 2025-10-01 18:18


NVD link : CVE-2025-2424

Mitre link : CVE-2025-2424

CVE.ORG link : CVE-2025-2424


JSON object : View

Products Affected

mattermost

  • mattermost_server
CWE
CWE-863

Incorrect Authorization