← Retour aux CVEs
CVE-2025-2571
MEDIUM4.2
Description
Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to clear Google OAuth credentials when converting user accounts to bot accounts, allowing attackers to gain unauthorized access to bot accounts via the Google OAuth signup flow.
Details CVE
Score CVSS v3.14.2
SeveriteMEDIUM
Vecteur CVSSCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Vecteur d'attaqueNETWORK
ComplexiteHIGH
Privileges requisLOW
Interaction utilisateurNONE
Publie5/30/2025
Derniere modification10/15/2025
Sourcenvd
Observations honeypot0
Produits affectes
mattermost:mattermost_server
Faiblesses (CWE)
CWE-303
References
https://mattermost.com/security-updates(responsibledisclosure@mattermost.com)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.