Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly invalidate personal access tokens upon user deactivation, allowing deactivated users to maintain full system access by exploiting access token validation flaws via continued usage of previously issued tokens.
References
| Link | Resource |
|---|---|
| https://mattermost.com/security-updates | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2025-05-30 15:15
Updated : 2025-10-15 14:16
NVD link : CVE-2025-3230
Mitre link : CVE-2025-3230
CVE.ORG link : CVE-2025-3230
JSON object : View
Products Affected
mattermost
- mattermost_server
CWE
CWE-303
Incorrect Implementation of Authentication Algorithm
