cbcvebase.
CVE-2025-3228
published 2025-06-20

CVE-2025-3228: Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly retrieve requestorInfo from…

medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly retrieve requestorInfo from playbooks handler for guest users which allows an attacker access to the playbook run.

Affected

22 ranges
VendorProductVersion rangeFixed in
github.commattermost_mattermost-server>= 0 < 0.0.0-20250520060012-d0380305ef7a0.0.0-20250520060012-d0380305ef7a
github.commattermost_mattermost-server>= 10.5.0+incompatible < 10.5.6+incompatible10.5.6+incompatible
github.commattermost_mattermost-server>= 10.6.0+incompatible < 10.6.6+incompatible10.6.6+incompatible
github.commattermost_mattermost-server>= 10.7.0+incompatible < 10.7.3+incompatible10.7.3+incompatible
github.commattermost_mattermost-server>= 10.8.0+incompatible < 10.8.1+incompatible10.8.1+incompatible
github.commattermost_mattermost-server>= 9.11.0+incompatible < 9.11.16+incompatible9.11.16+incompatible
github.commattermost_mattermost_server_v8>= 0 < 8.0.0-20250520060012-d0380305ef7a8.0.0-20250520060012-d0380305ef7a
github.commattermost_mattermost_server_v8>= 10.5.0 < 10.5.610.5.6
github.commattermost_mattermost_server_v8>= 10.6.0 < 10.6.610.6.6
github.commattermost_mattermost_server_v8>= 10.7.0 < 10.7.310.7.3
github.commattermost_mattermost_server_v8>= 10.8.0 < 10.8.110.8.1
github.commattermost_mattermost_server_v8>= 9.11.0 < 9.11.169.11.16
mattermostmattermost
mattermostmattermost10.5.0 – 10.5.5
mattermostmattermost10.6.0 – 10.6.5
mattermostmattermost10.7.0 – 10.7.2
mattermostmattermost9.11.0 – 9.11.15
mattermostmattermost_server
mattermostmattermost_server>= 10.5.0 < 10.5.610.5.6
mattermostmattermost_server>= 10.6.0 < 10.6.610.6.6
mattermostmattermost_server>= 10.7.0 < 10.7.310.7.3
mattermostmattermost_server>= 9.11.0 < 9.11.169.11.16