PT-2025-16245 · Mattermost · Mattermost

Vultza

·

Published

2025-04-14

·

Updated

2025-04-23

·

CVE-2025-2424

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Mattermost versions 10.5.x through 10.5.1 Mattermost versions 9.11.x through 9.11.9
Description: The issue allows an attacker who knows the IDs of deleted files to obtain metadata of the files via bookmark creation, as the software fails to check if a file has been deleted when creating a bookmark.
Recommendations: For versions 10.5.x through 10.5.1, update to a version later than 10.5.1 to resolve the issue. For versions 9.11.x through 9.11.9, update to a version later than 9.11.9 to resolve the issue. As a temporary workaround, consider restricting access to bookmark creation functionality until a patch is available.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-2424
GHSA-WWHJ-PW6H-F8HW
GO-2025-3611
OPENSUSE-SU-2025:15017-1

Affected Products

Mattermost