CVE-2025-4128 - Mattermost Guest User API Team Information Disclosure
CVE ID : CVE-2025-4128
Published : June 11, 2025, 11:15 a.m. | 1 hour, 3 minutes ago
Description : Mattermost versions 10.5.x <= 10.5.4, 9.11.x <= 9.11.13 fail to properly restrict API access to team information, allowing guest users to bypass permissions and view information about public teams they are not members of via a direct API call to /api/v4/teams/{team_id}.
Severity: 3.1 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : June 11, 2025, 11:15 a.m. | 1 hour, 3 minutes ago
Description : Mattermost versions 10.5.x <= 10.5.4, 9.11.x <= 9.11.13 fail to properly restrict API access to team information, allowing guest users to bypass permissions and view information about public teams they are not members of via a direct API call to /api/v4/teams/{team_id}.
Severity: 3.1 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...