CVE-2025-2527: Improper access control to group information
Published May 15, 2025
·Updated
Mattermost versions 10.5.x <= 10.5.2, 9.11.x <= 9.11.11 failed to properly verify a user's permissions when accessing groups, which allows an attacker to view group information via an API request.
Affected Software
6 affected componentsFixes available
Mattermost Mattermost<=10.5.2, <=9.11.11
go/github.com/mattermost/mattermost/server/v8<8.0.0-20250411064244-844447fbd57c
8.0.0-20250411064244-844447fbd57c
go/github.com/mattermost/mattermost/server/v8>=9.11.0<=9.11.11
9.11.12
go/github.com/mattermost/mattermost/server/v8>=10.5.0<=10.5.2
10.5.3
Mattermost Mattermost Server>=9.11.0<9.11.12
Mattermost Mattermost Server>=10.5.0<10.5.3
Remediation
Information
Update Mattermost to versions 10.7.0, 10.5.3, 9.11.12 or higher.
Event History
May 15, 2025
CVE Published
via MITRE·03:27 PM
Data Sourced
via MITRE·03:27 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
Affected Software
Advisory Published
via GitHub·06:31 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-2527?
CVE-2025-2527 is considered a moderate severity vulnerability due to improper verification of user permissions.
2
How do I fix CVE-2025-2527?
To fix CVE-2025-2527, upgrade to Mattermost versions 10.5.3 or 9.11.12 or later.
3
What versions of Mattermost are affected by CVE-2025-2527?
Mattermost versions 10.5.x up to and including 10.5.2 and 9.11.x up to and including 9.11.11 are affected by CVE-2025-2527.
4
What type of attacks can exploit CVE-2025-2527?
CVE-2025-2527 can be exploited to allow unauthorized access to group information via an API request.
5
Is there a workaround for CVE-2025-2527?
Currently, there is no documented workaround for CVE-2025-2527; upgrading to a fixed version is recommended.