Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8, 10.5.x <= 10.5.0 fail to restrict bookmark creation and updates in archived channels, which allows authenticated users created or update bookmarked in archived channels
References
History

Fri, 21 Mar 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Mar 2025 08:45:00 +0000

Type Values Removed Values Added
Description Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8, 10.5.x <= 10.5.0 fail to restrict bookmark creation and updates in archived channels, which allows authenticated users created or update bookmarked in archived channels
Title Unauthorized Bookmark Creation and Modification in Archived Channels
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published: 2025-03-21T08:25:44.676Z

Updated: 2025-03-21T12:28:00.367Z

Reserved: 2025-03-20T08:20:28.187Z

Link: CVE-2025-24920

cve-icon Vulnrichment

Updated: 2025-03-21T12:27:54.979Z

cve-icon NVD

Status : Received

Published: 2025-03-21T09:15:12.633

Modified: 2025-03-21T09:15:12.633

Link: CVE-2025-24920

cve-icon Redhat

No data.