CVE-2025-1472: Unauthorized View Access to Site Statistics and Team Statistics
Published Mar 19, 2025
·Updated
Mattermost versions 9.11.x <= 9.11.8 fail to properly perform authorization of the Viewer role which allows an attacker with the Viewer role configured with No Access to Reporting to still view team and site statistics.
Affected Software
4 affected componentsFixes available
Mattermost Mattermost<=9.11.8
go/github.com/mattermost/mattermost-server>=9.11.0<9.11.9
9.11.9
go/github.com/mattermost/mattermost/server/v8>=9.11.0<9.11.9
9.11.9
Mattermost Mattermost Server>=9.11.0<9.11.9
Remediation
Information
Update Mattermost to versions 10.5.0, 9.11.9 or higher.
Event History
Mar 19, 2025
CVE Published
via MITRE·02:11 PM
Data Sourced
via MITRE·02:11 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
Affected Software
Advisory Published
via GitHub·03:31 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-1472?
CVE-2025-1472 has a medium severity rating due to the improper authorization in the Viewer role.
2
How do I fix CVE-2025-1472?
To fix CVE-2025-1472, upgrade Mattermost to a version higher than 9.11.8.
3
What versions are affected by CVE-2025-1472?
CVE-2025-1472 affects Mattermost versions 9.11.x up to and including 9.11.8.
4
What is the risk associated with CVE-2025-1472?
The risk associated with CVE-2025-1472 is that users with restricted Viewer roles may access sensitive team and site statistics.
5
Is there a workaround for CVE-2025-1472?
There are no official workarounds for CVE-2025-1472; upgrading to a secure version is the recommended approach.