CVE-2025-3611 - Mattermost System Manager Access Control Enforcement Vulnerability
CVE ID : CVE-2025-3611
Published : May 30, 2025, 3:15 p.m. | 2 hours, 26 minutes ago
Description : Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly enforce access control restrictions for System Manager roles, allowing authenticated users with System Manager privileges to view team details they should not have access to via direct API requests to team endpoints, even when explicitly configured with 'No access' to Teams in the System Console.
Severity: 3.1 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : May 30, 2025, 3:15 p.m. | 2 hours, 26 minutes ago
Description : Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly enforce access control restrictions for System Manager roles, allowing authenticated users with System Manager privileges to view team details they should not have access to via direct API requests to team endpoints, even when explicitly configured with 'No access' to Teams in the System Console.
Severity: 3.1 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...