Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly enforce channel member management permissions in playbook runs, allowing authenticated users without the 'Manage Channel Members' permission to add or remove users from public and private channels by manipulating playbook run participants when the run is linked to a channel.
References
Link | Resource |
---|---|
https://mattermost.com/security-updates | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
08 Jul 2025, 14:31
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-06-20 15:15
Updated : 2025-07-08 14:31
NVD link : CVE-2025-3227
Mitre link : CVE-2025-3227
CVE.ORG link : CVE-2025-3227
JSON object : View
Products Affected
mattermost
- mattermost_server
CWE
CWE-863
Incorrect Authorization