CVE-2025-0503

Mattermost versions 9.11.x <= 9.11.6 fail to filter out DMs from the deleted channels endpoint which allows an attacker to infer user IDs and other metadata from deleted DMs if someone had manually marked DMs as deleted in the database.
References
Link Resource
https://mattermost.com/security-updates Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-02-14 18:15

Updated : 2025-09-29 18:11


NVD link : CVE-2025-0503

Mitre link : CVE-2025-0503

CVE.ORG link : CVE-2025-0503


JSON object : View

Products Affected

mattermost

  • mattermost_server
CWE
CWE-754

Improper Check for Unusual or Exceptional Conditions