Mattermost versions 9.11.x <= 9.11.8 fail to properly perform authorization of the Viewer role which allows an attacker with the Viewer role configured with No Access to Reporting to still view team and site statistics.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://mattermost.com/security-updates |
![]() ![]() |
History
Wed, 19 Mar 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 19 Mar 2025 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Mattermost versions 9.11.x <= 9.11.8 fail to properly perform authorization of the Viewer role which allows an attacker with the Viewer role configured with No Access to Reporting to still view team and site statistics. | |
Title | Unauthorized View Access to Site Statistics and Team Statistics | |
Weaknesses | CWE-863 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Mattermost
Published: 2025-03-19T14:11:03.977Z
Updated: 2025-03-19T14:40:59.930Z
Reserved: 2025-02-19T15:34:14.680Z
Link: CVE-2025-1472

Updated: 2025-03-19T14:39:59.425Z

Status : Received
Published: 2025-03-19T15:15:53.433
Modified: 2025-03-19T15:15:53.433
Link: CVE-2025-1472

No data.