CVE-2025-1792 Information
May 31, 2025
cve
Description
Mattermost versions 10.7.x <= 10.7.0 10.5.x <= 10.5.3 9.11.x <= 9.11.12 fail to properly enforce access controls for guest users accessing channel member information allowing authenticated guest users to view metadata about members of public channels via the channel members API endpoint.
Reference
https://mattermost.com/security-updates
Share on: