PT-2025-16792 · Mattermost · Mattermost

Hackit_Bharat

·

Published

2025-04-16

·

Updated

2025-04-23

·

CVE-2025-2564

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Mattermost versions 10.5.x through 10.5.1 Mattermost versions 10.4.x through 10.4.3 Mattermost versions 9.11.x through 9.11.9
Description The issue is related to the improper enforcement of the 'Allow users to view/update archived channels' System Console setting. This allows authenticated users to view members and member information of archived channels, even when this setting is disabled.
Recommendations For versions 10.5.x through 10.5.1, update to a version that properly enforces the System Console setting. For versions 10.4.x through 10.4.3, update to a version that properly enforces the System Console setting. For versions 9.11.x through 9.11.9, update to a version that properly enforces the System Console setting. As a temporary workaround, consider restricting access to archived channels to minimize the risk of exploitation.

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-2564
GHSA-MJ2P-V2C2-VH4V
GO-2025-3623
OPENSUSE-SU-2025:15017-1

Affected Products

Mattermost