Vulnerability Details CVE-2025-3228
Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly retrieve requestorInfo from playbooks handler for guest users which allows an attacker access to the playbook run.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 6.6%
CVSS Severity
CVSS v3 Score 4.3
Products affected by CVE-2025-3228
-
cpe:2.3:a:mattermost:mattermost_server:10.5.0
-
cpe:2.3:a:mattermost:mattermost_server:10.5.1
-
cpe:2.3:a:mattermost:mattermost_server:10.5.2
-
cpe:2.3:a:mattermost:mattermost_server:10.5.3
-
cpe:2.3:a:mattermost:mattermost_server:10.5.4
-
cpe:2.3:a:mattermost:mattermost_server:10.5.5
-
cpe:2.3:a:mattermost:mattermost_server:10.6.0
-
cpe:2.3:a:mattermost:mattermost_server:10.6.1
-
cpe:2.3:a:mattermost:mattermost_server:10.6.2
-
cpe:2.3:a:mattermost:mattermost_server:10.6.3
-
cpe:2.3:a:mattermost:mattermost_server:10.6.4
-
cpe:2.3:a:mattermost:mattermost_server:10.6.5
-
cpe:2.3:a:mattermost:mattermost_server:10.7.0
-
cpe:2.3:a:mattermost:mattermost_server:10.7.1
-
cpe:2.3:a:mattermost:mattermost_server:10.7.2
-
cpe:2.3:a:mattermost:mattermost_server:10.8.0
-
cpe:2.3:a:mattermost:mattermost_server:9.11.0
-
cpe:2.3:a:mattermost:mattermost_server:9.11.1
-
cpe:2.3:a:mattermost:mattermost_server:9.11.10
-
cpe:2.3:a:mattermost:mattermost_server:9.11.11
-
cpe:2.3:a:mattermost:mattermost_server:9.11.12
-
cpe:2.3:a:mattermost:mattermost_server:9.11.13
-
cpe:2.3:a:mattermost:mattermost_server:9.11.14
-
cpe:2.3:a:mattermost:mattermost_server:9.11.15
-
cpe:2.3:a:mattermost:mattermost_server:9.11.2
-
cpe:2.3:a:mattermost:mattermost_server:9.11.3
-
cpe:2.3:a:mattermost:mattermost_server:9.11.4
-
cpe:2.3:a:mattermost:mattermost_server:9.11.5
-
cpe:2.3:a:mattermost:mattermost_server:9.11.6
-
cpe:2.3:a:mattermost:mattermost_server:9.11.7
-
cpe:2.3:a:mattermost:mattermost_server:9.11.8
-
cpe:2.3:a:mattermost:mattermost_server:9.11.9