CVE-2025-2571
4.2
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Exploitability: 1.6 / Impact: 2.5
Source: responsibledisclosure@mattermost.com (Secondary)
Description
Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to clear Google OAuth credentials when converting user accounts to bot accounts, allowing attackers to gain unauthorized access to bot accounts via the Google OAuth signup flow.
Affected (4)
Products: Mattermost: Mattermost Server
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 10.5.0 to 10.5.4 |
References (1)
Timeline
No history available yet.