CVE-2025-25274

Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to restrict command execution in archived channels, which allows authenticated users to run commands in archived channels.
References
Link Resource
https://mattermost.com/security-updates Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*

History

27 Mar 2025, 15:01

Type Values Removed Values Added
CPE cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
CWE CWE-77
References () https://mattermost.com/security-updates - () https://mattermost.com/security-updates - Vendor Advisory
Summary
  • (es) Las versiones de Mattermost 10.4.x &lt;= 10.4.2, 10.3.x &lt;= 10.3.3, 9.11.x &lt;= 9.11.8 no logran restringir la ejecución de comandos en canales archivados, lo que permite que los usuarios autenticados ejecuten comandos en canales archivados.
First Time Mattermost mattermost Server
Mattermost

21 Mar 2025, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-21 09:15

Updated : 2025-03-27 15:01


NVD link : CVE-2025-25274

Mitre link : CVE-2025-25274

CVE.ORG link : CVE-2025-25274


JSON object : View

Products Affected

mattermost

  • mattermost_server
CWE
CWE-863

Incorrect Authorization

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')