CVE-2025-1472

Source
https://cve.org/CVERecord?id=CVE-2025-1472
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-1472.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-1472
Aliases
Downstream
Related
Published
2025-03-19T14:11:03.977Z
Modified
2026-07-15T01:48:53.084814611Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Unauthorized View Access to Site Statistics and Team Statistics
Details

Mattermost versions 9.11.x <= 9.11.8 fail to properly perform authorization of the Viewer role which allows an attacker with the Viewer role configured with No Access to Reporting to still view team and site statistics.

Database specific
{
    "cna_assigner": "Mattermost",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/1xxx/CVE-2025-1472.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "9.11.0"
                },
                {
                    "last_affected": "9.11.8"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ],
    "cwe_ids": [
        "CWE-863"
    ]
}
References

Affected packages

Git / github.com/mattermost/mattermost

Affected ranges

Type
GIT
Repo
https://github.com/mattermost/mattermost
Events
Database specific
{
    "cpe": "cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "9.11.0"
        },
        {
            "fixed": "9.11.9"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

@mattermost/client@9.*
@mattermost/client@9.11.0
@mattermost/types@9.*
@mattermost/types@9.11.0
v9.*
v9.11.0
v9.11.0-rc3
v9.11.1
v9.11.1-rc1
v9.11.2
v9.11.2-rc1
v9.11.2-rc2
v9.11.3
v9.11.3-rc1
v9.11.3-rc2
v9.11.4
v9.11.4-rc1
v9.11.5
v9.11.5-rc1
v9.11.6
v9.11.6-rc1
v9.11.6-rc2
v9.11.7
v9.11.7-rc1
v9.11.7-rc2
v9.11.7-rc3
v9.11.8
v9.11.9-rc1
v9.11.9-rc2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-1472.json"