CVE-2025-4128
Mattermost Guest User Information Disclosure Vulnerability
Severity Score
3.1
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
Track
*SSVC
Descriptions
Mattermost versions 10.5.x <= 10.5.4, 9.11.x <= 9.11.13 fail to properly restrict API access to team information, allowing guest users to bypass permissions and view information about public teams they are not members of via a direct API call to /api/v4/teams/{team_id}.
Las versiones de Mattermost 10.5.x <= 10.5.4, 9.11.x <= 9.11.13 no restringen adecuadamente el acceso de la API a la información del equipo, lo que permite que los usuarios invitados omitan los permisos y vean información sobre equipos públicos de los que no son miembros a través de una llamada API directa a /api/v4/teams/{team_id}.
*Credits:
hackit_bharat
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Track
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2025-04-30 CVE Reserved
- 2025-06-11 CVE Published
- 2025-06-11 CVE Updated
- 2025-06-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-863: Incorrect Authorization
CAPEC
References (1)
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mattermost Search vendor "Mattermost" | Mattermost Search vendor "Mattermost" for product "Mattermost" | >= 10.5.0 <= 10.5.4 Search vendor "Mattermost" for product "Mattermost" and version " >= 10.5.0 <= 10.5.4" | en |
Affected
| ||||||
Mattermost Search vendor "Mattermost" | Mattermost Search vendor "Mattermost" for product "Mattermost" | >= 9.11.0 <= 9.11.13 Search vendor "Mattermost" for product "Mattermost" and version " >= 9.11.0 <= 9.11.13" | en |
Affected
|