CVE-2025-1472
published 2025-03-19CVE-2025-1472: Mattermost versions 9.11.x <= 9.11.8 fail to properly perform authorization of the Viewer role which allows an attacker with the Viewer role configured with No…
PriorityP422medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
0.23%
14.3th percentile
Mattermost versions 9.11.x <= 9.11.8 fail to properly perform authorization of the Viewer role which allows an attacker with the Viewer role configured with No Access to Reporting to still view team and site statistics.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | mattermost_mattermost-server | >= 9.11.0 < 9.11.9 | 9.11.9 |
| github.com | mattermost_mattermost-server | >= 9.11.0+incompatible < 9.11.9+incompatible | 9.11.9+incompatible |
| github.com | mattermost_mattermost_server_v8 | >= 9.11.0 < 9.11.9 | 9.11.9 |
| mattermost | mattermost | 9.11.0 – 9.11.8 | — |
| mattermost | mattermost_server | >= 9.11.0 < 9.11.9 | 9.11.9 |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Mattermost Fails to Properly Perform Viewer Role Authorization in github.com/mattermost/mattermost-server
osv·2025-03-25
CVE-2025-1472 Mattermost Fails to Properly Perform Viewer Role Authorization in github.com/mattermost/mattermost-server
Mattermost Fails to Properly Perform Viewer Role Authorization in github.com/mattermost/mattermost-server
Mattermost Fails to Properly Perform Viewer Role Authorization in github.com/mattermost/mattermost-server
OSV
Mattermost Fails to Properly Perform Viewer Role Authorization
osv·2025-03-19
CVE-2025-1472 [MEDIUM] Mattermost Fails to Properly Perform Viewer Role Authorization
Mattermost Fails to Properly Perform Viewer Role Authorization
Mattermost versions 9.11.x <= 9.11.8 fail to properly perform authorization of the Viewer role which allows an attacker with the Viewer role configured with No Access to Reporting to still view team and site statistics.
GHSA
Mattermost Fails to Properly Perform Viewer Role Authorization
ghsa·2025-03-19
CVE-2025-1472 [MEDIUM] CWE-863 Mattermost Fails to Properly Perform Viewer Role Authorization
Mattermost Fails to Properly Perform Viewer Role Authorization
Mattermost versions 9.11.x <= 9.11.8 fail to properly perform authorization of the Viewer role which allows an attacker with the Viewer role configured with No Access to Reporting to still view team and site statistics.
Red Hat
kernel: RDMA/core: Fix "KASAN: slab-use-after-free Read in ib_register_device" problem
vendor_redhat·2025-06-18·CVSS 7.8
CVE-2025-38022 [HIGH] CWE-125 kernel: RDMA/core: Fix "KASAN: slab-use-after-free Read in ib_register_device" problem
kernel: RDMA/core: Fix "KASAN: slab-use-after-free Read in ib_register_device" problem
In the Linux kernel, the following vulnerability has been resolved:
RDMA/core: Fix "KASAN: slab-use-after-free Read in ib_register_device" problem
Call Trace:
__dump_stack lib/dump_stack.c:94 [inline]
dump_stack_lvl+0x116/0x1f0 lib/dump_stack.c:120
print_address_description mm/kasan/report.c:408 [inline]
print_report+0xc3/0x670 mm/kasan/report.c:521
kasan_report+0xe0/0x110 mm/kasan/report.c:634
strlen+0x93/0xa0 lib/string.c:420
__fortify_strlen include/linux/fortify-string.h:268 [inline]
get_kobj_path_length lib/kobject.c:118 [inline]
kobject_get_path+0x3f/0x2a0 lib/kobject.c:158
kobject_uevent_env+0x289/0x1870 lib/kobject_uevent.c:545
ib_register_device drivers/infiniband/core/device.c:1472 [inline]
ib
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-03-19
Published