Mattermost versions 10.5.x <= 10.5.3, 9.11.x <= 9.11.11 fail to check `RestrictSystemAdmin` setting if user doesn't have access to `ExperimentalSettings` which allows a System Manager to access `ExperimentSettings` when `RestrictSystemAdmin` is true via System Console.
References
History

Thu, 15 May 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 15 May 2025 15:45:00 +0000

Type Values Removed Values Added
Description Mattermost versions 10.5.x <= 10.5.3, 9.11.x <= 9.11.11 fail to check `RestrictSystemAdmin` setting if user doesn't have access to `ExperimentalSettings` which allows a System Manager to access `ExperimentSettings` when `RestrictSystemAdmin` is true via System Console.
Title System Admin Cannot Access Environment settings in System Console While System Manager Can
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published: 2025-05-15T15:27:50.280Z

Updated: 2025-05-15T15:47:16.151Z

Reserved: 2025-03-20T19:30:43.161Z

Link: CVE-2025-2570

cve-icon Vulnrichment

Updated: 2025-05-15T15:47:13.736Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-05-15T16:15:33.563

Modified: 2025-05-16T14:43:26.160

Link: CVE-2025-2570

cve-icon Redhat

No data.