Vulnerability Details CVE-2025-2424
Mattermost versions 10.5.x <= 10.5.1, 9.11.x <= 9.11.9 fail to check if a file has been deleted when creating a bookmark which allows an attacker who knows the IDs of deleted files to obtain metadata of the files via bookmark creation.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 7.3%
CVSS Severity
CVSS v3 Score 3.1
Products affected by CVE-2025-2424
-
cpe:2.3:a:mattermost:mattermost_server:10.5.0
-
cpe:2.3:a:mattermost:mattermost_server:10.5.1
-
cpe:2.3:a:mattermost:mattermost_server:9.11.0
-
cpe:2.3:a:mattermost:mattermost_server:9.11.1
-
cpe:2.3:a:mattermost:mattermost_server:9.11.2
-
cpe:2.3:a:mattermost:mattermost_server:9.11.3
-
cpe:2.3:a:mattermost:mattermost_server:9.11.4
-
cpe:2.3:a:mattermost:mattermost_server:9.11.5
-
cpe:2.3:a:mattermost:mattermost_server:9.11.6
-
cpe:2.3:a:mattermost:mattermost_server:9.11.7
-
cpe:2.3:a:mattermost:mattermost_server:9.11.8
-
cpe:2.3:a:mattermost:mattermost_server:9.11.9