Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly validate channel membership when retrieving playbook run metadata, allowing authenticated users who are playbook members but not channel members to access sensitive information about linked private channels including channel name, display name, and participant count through the run metadata API endpoint.
References
History

Mon, 30 Jun 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 30 Jun 2025 17:00:00 +0000

Type Values Removed Values Added
Description Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly validate channel membership when retrieving playbook run metadata, allowing authenticated users who are playbook members but not channel members to access sensitive information about linked private channels including channel name, display name, and participant count through the run metadata API endpoint.
Title Mattermost Playbooks exposes private channel metadata to unauthorized users via run metadata API
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published: 2025-06-30T16:51:13.979Z

Updated: 2025-06-30T20:48:41.938Z

Reserved: 2025-05-23T09:42:12.046Z

Link: CVE-2025-47871

cve-icon Vulnrichment

Updated: 2025-06-30T20:48:39.016Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-30T17:15:32.777

Modified: 2025-06-30T18:38:23.493

Link: CVE-2025-47871

cve-icon Redhat

No data.