CVE-2025-1792 - Mattermost Guest Access Control Vulnerability
CVE ID : CVE-2025-1792
Published : May 30, 2025, 3:15 p.m. | 25 minutes ago
Description : Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to properly enforce access controls for guest users accessing channel member information, allowing authenticated guest users to view metadata about members of public channels via the channel members API endpoint.
Severity: 3.1 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : May 30, 2025, 3:15 p.m. | 25 minutes ago
Description : Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to properly enforce access controls for guest users accessing channel member information, allowing authenticated guest users to view metadata about members of public channels via the channel members API endpoint.
Severity: 3.1 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...