Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-322v-vh2g-qvpv: Mattermost Fails to Restrict Certain Operations on System Admins

Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to restrict certain operations on system admins to only other system admins, which allows delegated granular administration users with the “Edit Other Users” permission to perform unauthorized modifications to system administrators via improper permission validation.

ghsa
#git#auth
  1. GitHub Advisory Database
  2. GitHub Reviewed
  3. CVE-2025-32093

Mattermost Fails to Restrict Certain Operations on System Admins

Moderate severity GitHub Reviewed Published Apr 14, 2025 to the GitHub Advisory Database • Updated Apr 14, 2025

Package

gomod github.com/mattermost/mattermost-server (Go)

Affected versions

>= 10.5.0, < 10.5.2

>= 10.4.0, < 10.4.4

>= 9.11.0, < 9.11.10

Patched versions

10.5.2

10.4.4

9.11.10

gomod github.com/mattermost/mattermost/server/v8 (Go)

>= 10.5.0, < 10.5.2

>= 10.4.0, < 10.4.4

>= 9.11.0, < 9.11.10

< 8.0.0-20250227102013-aa4623a93199

10.5.2

10.4.4

9.11.10

8.0.0-20250227102013-aa4623a93199

Published to the GitHub Advisory Database

Apr 14, 2025

Last updated

Apr 14, 2025

ghsa: Latest News

GHSA-qfm8-78qf-p75j: The Front End User Registration extension for TYPO3 (sr_feuser_register) Remote Code Execution