CVE-2025-2570
15.05.2025, 16:15
Mattermost versions 10.5.x <= 10.5.3, 9.11.x <= 9.11.11 fail to check `RestrictSystemAdmin` setting if user doesn't have access to `ExperimentalSettings` which allows a System Manager to access `ExperimentSettings` when `RestrictSystemAdmin` is true via System Console.Enginsight
Vendor | Product | Version |
---|---|---|
mattermost | mattermost_server | 9.11.0 ≤ 𝑥 < 9.11.12 |
mattermost | mattermost_server | 10.5.0 ≤ 𝑥 < 10.5.4 |
𝑥
= Vulnerable software versions
References