CVE-2025-0503

Mattermost versions 9.11.x <= 9.11.6 fail to filter out DMs from the deleted channels endpoint which allows an attacker to infer user IDs and other metadata from deleted DMs if someone had manually marked DMs as deleted in the database.
References
Configurations

No configuration.

History

14 Feb 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-14 18:15

Updated : 2025-02-14 18:15


NVD link : CVE-2025-0503

Mitre link : CVE-2025-0503

CVE.ORG link : CVE-2025-0503


JSON object : View

Products Affected

No product.

CWE
CWE-754

Improper Check for Unusual or Exceptional Conditions