CVE-2025-3230: Bypass of System Admin User Deactivation Controls for Personal Access Tokens in Mattermost Server
Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly invalidate personal access tokens upon user deactivation, allowing deactivated users to maintain full system access by exploiting access token validation flaws via continued usage of previously issued tokens.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3230?
CVE-2025-3230 is classified as a critical vulnerability due to its potential to allow deactivated users to maintain full system access.
How do I fix CVE-2025-3230?
To fix CVE-2025-3230, update Mattermost Server to a version beyond 10.7.0, 10.6.2, 10.5.3, or 9.11.12.
Which versions of Mattermost are affected by CVE-2025-3230?
CVE-2025-3230 affects Mattermost Server versions 10.7.0 and earlier, 10.6.2 and earlier, 10.5.3 and earlier, and 9.11.12 and earlier.
What impact does CVE-2025-3230 have on system security?
The impact of CVE-2025-3230 is significant as it allows deactivated users to exploit access tokens, compromising system security.
Is there a workaround for CVE-2025-3230?
Currently, the primary mitigation for CVE-2025-3230 is to upgrade to a non-vulnerable version of Mattermost Server.