CVE-2025-24920: Unauthorized Bookmark Creation and Modification in Archived Channels
Published Mar 21, 2025
·Updated
Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8, 10.5.x <= 10.5.0 fail to restrict bookmark creation and updates in archived channels, which allows authenticated users created or update bookmarked in archived channels
Affected Software
9 affected componentsFixes available
Mattermost Mattermost<=10.4.2, <=10.3.3, <=9.11.8, <=10.5.0
go/github.com/mattermost/mattermost/server/v8=10.5.0
10.5.1
go/github.com/mattermost/mattermost/server/v8>=9.11.0<9.11.9
9.11.9
go/github.com/mattermost/mattermost/server/v8>=10.3.0<10.3.4
10.3.4
go/github.com/mattermost/mattermost/server/v8>=10.4.0<10.4.3
10.4.3
Mattermost Mattermost Server>=9.11.0<9.11.9
Mattermost Mattermost Server>=10.3.0<10.3.4
Mattermost Mattermost Server>=10.4.0<10.4.3
Mattermost Mattermost Server>=10.5.0<10.5.1
Remediation
Information
Update Mattermost to versions 10.6.0, 10.4.3, 10.3.4, 9.11.9, 10.5.1 or higher.
Event History
Mar 21, 2025
CVE Published
via MITRE·08:25 AM
Data Sourced
via MITRE·08:25 AM
RemedyDescriptionSeverityWeakness
Advisory Published
via GitHub·09:30 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-24920?
CVE-2025-24920 is classified as a medium-severity vulnerability.
2
How do I fix CVE-2025-24920?
To fix CVE-2025-24920, upgrade Mattermost to versions 10.4.3, 10.3.4, 9.11.9, or 10.5.1 or later.
3
Who is affected by CVE-2025-24920?
CVE-2025-24920 affects Mattermost versions 10.4.x up to 10.4.2, 10.3.x up to 10.3.3, 9.11.x up to 9.11.8, and 10.5.x up to 10.5.0.
4
What type of attack is associated with CVE-2025-24920?
CVE-2025-24920 allows authenticated users to create or update bookmarks in archived channels without restriction.
5
Is there a workaround for CVE-2025-24920?
Currently, there are no official workarounds for CVE-2025-24920; upgrading is the recommended solution.