Mattermost versions 10.5.x <= 10.5.1, 9.11.x <= 9.11.9 fail to check if a file has been deleted when creating a bookmark which allows an attacker who knows the IDs of deleted files to obtain metadata of the files via bookmark creation.
References
History

Mon, 14 Apr 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Apr 2025 15:00:00 +0000

Type Values Removed Values Added
Description Mattermost versions 10.5.x <= 10.5.1, 9.11.x <= 9.11.9 fail to check if a file has been deleted when creating a bookmark which allows an attacker who knows the IDs of deleted files to obtain metadata of the files via bookmark creation.
Title Leaked Metadata of Deleted Files via Bookmark Creation
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published: 2025-04-14T14:49:35.783Z

Updated: 2025-04-14T15:00:45.367Z

Reserved: 2025-03-17T14:44:42.044Z

Link: CVE-2025-2424

cve-icon Vulnrichment

Updated: 2025-04-14T15:00:31.949Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-14T15:15:24.630

Modified: 2025-04-15T18:39:27.967

Link: CVE-2025-2424

cve-icon Redhat

No data.