CVE-2025-24866

Mattermost versions 9.11.x <= 9.11.8  fail to enforce proper access controls on the /api/v4/audits endpoint, allowing users with delegated granular administration roles who lack access to Compliance Monitoring to retrieve User Activity Logs.
References
Configurations

No configuration.

History

11 Apr 2025, 15:39

Type Values Removed Values Added
Summary
  • (es) Las versiones 9.11.x &lt;= 9.11.8 de Mattermost no implementan controles de acceso adecuados en el endpoint /api/v4/audits, lo que permite que los usuarios con roles de administración granular delegados que no tienen acceso a la Supervisión de cumplimiento recuperen registros de actividad del usuario.

10 Apr 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-10 16:15

Updated : 2025-04-11 15:39


NVD link : CVE-2025-24866

Mitre link : CVE-2025-24866

CVE.ORG link : CVE-2025-24866


JSON object : View

Products Affected

No product.

CWE
CWE-863

Incorrect Authorization