CVE-2025-2571 Google OAuth Authentication Bypass for Converted Bot Accounts
Discription

image
Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to clear Google OAuth credentials when converting user accounts to bot accounts, allowing attackers to gain unauthorized access to bot accounts via the Google OAuth signup…Read More

Back to Main

Subscribe for the latest news: