CVE-2025-4573
LDAP Injection in Mattermost Enterprise Edition When Using Active Directory
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Mattermost versions 10.7.x <= 10.7.1, 10.6.x <= 10.6.3, 10.5.x <= 10.5.4, 9.11.x <= 9.11.13 fail to properly validate LDAP group ID attributes, allowing an authenticated administrator with PermissionSysconsoleWriteUserManagementGroups permission to execute LDAP search filter injection via the PUT /api/v4/ldap/groups/{remote_id}/link API when objectGUID is configured as the Group ID Attribute.
Las versiones de Mattermost 10.7.x <= 10.7.1, 10.6.x <= 10.6.3, 10.5.x <= 10.5.4, 9.11.x <= 9.11.13 no logran validar correctamente los atributos de ID de grupo LDAP, lo que permite que un administrador autenticado con permiso PermissionSysconsoleWriteUserManagementGroups ejecute la inyección de filtro de búsqueda LDAP a través de la API PUT /api/v4/ldap/groups/{remote_id}/link cuando objectGUID está configurado como el atributo de ID de grupo.
These are all security issues fixed in the govulncheck-vulndb-0.0.20250612T141001-1.1 package on the GA media of openSUSE Tumbleweed.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2025-05-12 CVE Reserved
- 2025-06-11 CVE Published
- 2025-06-11 CVE Updated
- 2025-07-13 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-90: Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')
CAPEC
References (1)
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mattermost Search vendor "Mattermost" | Mattermost Search vendor "Mattermost" for product "Mattermost" | >= 10.7.0 <= 10.7.1 Search vendor "Mattermost" for product "Mattermost" and version " >= 10.7.0 <= 10.7.1" | en |
Affected
| ||||||
Mattermost Search vendor "Mattermost" | Mattermost Search vendor "Mattermost" for product "Mattermost" | >= 10.6.0 <= 10.6.3 Search vendor "Mattermost" for product "Mattermost" and version " >= 10.6.0 <= 10.6.3" | en |
Affected
| ||||||
Mattermost Search vendor "Mattermost" | Mattermost Search vendor "Mattermost" for product "Mattermost" | >= 10.5.0 <= 10.5.4 Search vendor "Mattermost" for product "Mattermost" and version " >= 10.5.0 <= 10.5.4" | en |
Affected
| ||||||
Mattermost Search vendor "Mattermost" | Mattermost Search vendor "Mattermost" for product "Mattermost" | >= 9.11.0 <= 9.11.13 Search vendor "Mattermost" for product "Mattermost" and version " >= 9.11.0 <= 9.11.13" | en |
Affected
|