CVE-2025-2424: Leaked Metadata of Deleted Files via Bookmark Creation
Published Apr 14, 2025
·Updated
Mattermost versions 10.5.x <= 10.5.1, 9.11.x <= 9.11.9 fail to check if a file has been deleted when creating a bookmark which allows an attacker who knows the IDs of deleted files to obtain metadata of the files via bookmark creation.
Affected Software
7 affected componentsFixes available
Mattermost Mattermost<=10.5.1
Mattermost Mattermost<=9.11.9
go/github.com/mattermost/mattermost/server/v8<8.0.0-20250213231113-68c11e9ecb71
8.0.0-20250213231113-68c11e9ecb71
go/github.com/mattermost/mattermost/server/v8>=9.11.0<9.11.10
9.11.10
go/github.com/mattermost/mattermost/server/v8>=10.5.0<10.5.2
10.5.2
Mattermost Mattermost Server>=9.11.0<9.11.10
Mattermost Mattermost Server>=10.5.0<10.5.2
Remediation
Information
Update Mattermost to versions 10.6.0, 10.5.2, 9.11.10 or higher.
Event History
Apr 14, 2025
CVE Published
via MITRE·02:49 PM
Data Sourced
via MITRE·02:49 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
Affected Software
Advisory Published
via GitHub·03:31 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-2424?
CVE-2025-2424 is considered a medium severity vulnerability due to potential information exposure.
2
How do I fix CVE-2025-2424?
To fix CVE-2025-2424, update Mattermost to a version later than 10.5.1 or 9.11.9.
3
What impact does CVE-2025-2424 have on Mattermost users?
CVE-2025-2424 allows attackers to access metadata of deleted files through bookmark creation, risking user privacy.
4
Is CVE-2025-2424 a zero-day vulnerability?
CVE-2025-2424 is not classified as a zero-day vulnerability, as it can be mitigated by applying available software updates.
5
Which versions of Mattermost are affected by CVE-2025-2424?
Mattermost versions 10.5.x up to 10.5.1 and 9.11.x up to 9.11.9 are affected by CVE-2025-2424.