CVE-2025-3227:
Mattermost allows unauthorized channel member management through playbook runs
4.3
CVSS Score
3.1
Basic Information
CVE ID
GHSA ID
EPSS Score
0.04441%
CWE
Published
6/20/2025
Updated
6/20/2025
KEV Status
No
Technology
Go
Technical Details
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
---|---|---|---|
github.com/mattermost/mattermost-server | go | < 0.0.0-20250520060012-d0380305ef7a | 0.0.0-20250520060012-d0380305ef7a |
github.com/mattermost/mattermost/server/v8 | go | < 8.0.0-20250520060012-d0380305ef7a | 8.0.0-20250520060012-d0380305ef7a |
github.com/mattermost/mattermost/server/v8 | go | >= 10.5.0, <= 10.5.5 | 10.5.6 |
github.com/mattermost/mattermost/server/v8 | go | >= 9.11.0, <= 9.11.15 | 9.11.16 |
github.com/mattermost/mattermost/server/v8 | go | = 10.8.0 | 10.8.1 |
github.com/mattermost/mattermost/server/v8 | go | >= 10.7.0, <= 10.7.2 | 10.7.3 |
github.com/mattermost/mattermost/server/v8 | go | >= 10.6.0, <= 10.6.5 | 10.6.6 |