CVE-2025-1472Incorrect Authorization in Mattermost Mattermost-server

Severity
4.3MEDIUMNVD
EPSS
0.1%
top 72.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 19
Latest updateJun 18

Description

Mattermost versions 9.11.x <= 9.11.8 fail to properly perform authorization of the Viewer role which allows an attacker with the Viewer role configured with No Access to Reporting to still view team and site statistics.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages4 packages

NVDmattermost/mattermost_server9.11.09.11.9
Gogithub.com/mattermost_mattermost-server9.11.0+incompatible9.11.9+incompatible+1
CVEListV5mattermost/mattermost9.11.09.11.8

🔴Vulnerability Details

4
OSV
Mattermost Fails to Properly Perform Viewer Role Authorization in github.com/mattermost/mattermost-server2025-03-25
CVEList
Unauthorized View Access to Site Statistics and Team Statistics2025-03-19
OSV
Mattermost Fails to Properly Perform Viewer Role Authorization2025-03-19
GHSA
Mattermost Fails to Properly Perform Viewer Role Authorization2025-03-19

📋Vendor Advisories

1
Red Hat
kernel: RDMA/core: Fix "KASAN: slab-use-after-free Read in ib_register_device" problem2025-06-18
CVE-2025-1472 — Incorrect Authorization | cvebase