Mattermost versions 9.11.x <= 9.11.8 fail to properly perform authorization of the Viewer role which allows an attacker with the Viewer role configured with No Access to Reporting to still view team and site statistics.
References
History

Wed, 19 Mar 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Mar 2025 14:30:00 +0000

Type Values Removed Values Added
Description Mattermost versions 9.11.x <= 9.11.8 fail to properly perform authorization of the Viewer role which allows an attacker with the Viewer role configured with No Access to Reporting to still view team and site statistics.
Title Unauthorized View Access to Site Statistics and Team Statistics
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published: 2025-03-19T14:11:03.977Z

Updated: 2025-03-19T14:40:59.930Z

Reserved: 2025-02-19T15:34:14.680Z

Link: CVE-2025-1472

cve-icon Vulnrichment

Updated: 2025-03-19T14:39:59.425Z

cve-icon NVD

Status : Received

Published: 2025-03-19T15:15:53.433

Modified: 2025-03-19T15:15:53.433

Link: CVE-2025-1472

cve-icon Redhat

No data.