Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-86jg-35xj-3vv5: Mattermost fails to properly enforce access control restrictions for System Manager roles

Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly enforce access control restrictions for System Manager roles, allowing authenticated users with System Manager privileges to view team details they should not have access to via direct API requests to team endpoints, even when explicitly configured with ‘No access’ to Teams in the System Console.

ghsa
#git#perl#auth
  1. GitHub Advisory Database
  2. GitHub Reviewed
  3. CVE-2025-3611

Mattermost fails to properly enforce access control restrictions for System Manager roles

Low severity GitHub Reviewed Published May 30, 2025 to the GitHub Advisory Database • Updated May 30, 2025

Package

gomod github.com/mattermost/mattermost/server/v8 (Go)

Affected versions

>= 10.6.0-rc1, < 10.7.1

>= 10.0.0-rc1, < 10.5.4

>= 9.0.0-rc1, < 9.11.13

< 8.0.0-20250414154356-6f33b721de76

Patched versions

10.7.1

10.5.4

9.11.13

8.0.0-20250414154356-6f33b721de76

Published to the GitHub Advisory Database

May 30, 2025

Last updated

May 30, 2025

ghsa: Latest News

GHSA-wv8j-m3hx-924j: Arrow2 allows out of bounds access in public safe API