CVE-2025-2475

Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to invalidate the cache when a user account is converted to a bot which allows an attacker to login to the bot exactly one time via normal credentials.
References
Configurations

No configuration.

History

15 Apr 2025, 18:39

Type Values Removed Values Added
Summary
  • (es) Las versiones de Mattermost 10.5.x &lt;= 10.5.1, 10.4.x &lt;= 10.4.3, 9.11.x &lt;= 9.11.9 no invalidan el caché cuando una cuenta de usuario se convierte en un bot, lo que permite a un atacante iniciar sesión en el bot exactamente una vez a través de credenciales normales.

14 Apr 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-14 15:15

Updated : 2025-04-15 18:39


NVD link : CVE-2025-2475

Mitre link : CVE-2025-2475

CVE.ORG link : CVE-2025-2475


JSON object : View

Products Affected

No product.

CWE
CWE-303

Incorrect Implementation of Authentication Algorithm