Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to fail to enforce channel conversion restrictions, which allows members with permission to convert public channels to private ones to also convert private ones to public
References
History

Fri, 21 Mar 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Mar 2025 08:45:00 +0000

Type Values Removed Values Added
Description Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to fail to enforce channel conversion restrictions, which allows members with permission to convert public channels to private ones to also convert private ones to public
Title Unauthorized Private-to-Public Channel Conversion
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published: 2025-03-21T08:23:20.955Z

Updated: 2025-03-21T13:32:57.219Z

Reserved: 2025-03-20T08:20:28.128Z

Link: CVE-2025-27933

cve-icon Vulnrichment

Updated: 2025-03-21T13:32:41.162Z

cve-icon NVD

Status : Received

Published: 2025-03-21T09:15:13.260

Modified: 2025-03-21T09:15:13.260

Link: CVE-2025-27933

cve-icon Redhat

No data.