Mattermost fails to properly enforce access control restrictions for System Manager roles

Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly enforce access control restrictions for System Manager roles, allowing authenticated us ...

Continue Reading
CVE-2025-5360

creation_timestamp| type| source ---|---|--- 2025-05-30 20:15:47+00:00| seen|...Read More ...

Continue Reading
Mattermost fails to properly enforce access controls for guest users

Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to properly enforce access controls for guest users accessing channel member information, allowing a ...

Continue Reading
CVE-2025-48948

creation_timestamp| type| source ---|---|--- 2025-05-30 20:15:27+00:00| seen|...Read More ...

Continue Reading
CVE-2025-48882

creation_timestamp| type| source ---|---|--- 2025-05-30 20:15:02+00:00| seen|...Read More ...

Continue Reading
CVE-2025-48946

creation_timestamp| type| source ---|---|--- 2025-05-30 20:20:02+00:00| seen|...Read More ...

Continue Reading
CVE-2025-5361

creation_timestamp| type| source ---|---|--- 2025-05-30 20:15:26+00:00| seen|...Read More ...

Continue Reading
Arrow2 allows out of bounds access in public safe API

Rows::row_unchecked() allows out of bounds access to the underlying buffer without sufficient checks. The arrow2 crate is no longer maintained, so there are no plans to fix this issue. Users are advis ...

Continue Reading

Back to Main

Subscribe for the latest news: