CVE-2025-1412 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

Mattermost versions 9.11.x
Low CVSS: 3.1

CVE-2025-1412

Mattermost versions 9.11.x <= 9.11.6, 10.4.x <= 10.4.1 fail to invalidate all active sessions when converting a user to a bot, with allows the converted user to escalate their privileges depending on the permissions granted to the bot.
Vendor
Mattermost
Product
Mattermost Server
CWE
CWE-384
Yayın Tarihi
2025-02-24 08:15:09
Güncelleme
2025-10-01 18:02:32
Source Identifier
responsibledisclosure@mattermost.com
KEV Date Added
-

Kategoriler

Referanslar