Mattermost Server 10.4.0 Release Candidate 1

CPE Details

Mattermost Server 10.4.0 Release Candidate 1
10.4.0
2025-01-10
17h38 +00:00
2025-01-10
17h38 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:mattermost:mattermost_server:10.4.0:rc1:*:*:*:*:*:*

Informations

Vendor

mattermost

Product

mattermost_server

Version

10.4.0

Update

rc1

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2025-25068 2025-03-21 08h26 +00:00 Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8, 10.5.x <= 10.5.0 fail to enforce MFA on plugin endpoints, which allows authenticated attackers to bypass MFA protections via API requests to plugin-specific routes.
8.8
High
CVE-2025-24920 2025-03-21 08h25 +00:00 Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8, 10.5.x <= 10.5.0 fail to restrict bookmark creation and updates in archived channels, which allows authenticated users created or update bookmarked in archived channels
4.3
Medium
CVE-2025-30179 2025-03-21 08h24 +00:00 Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to enforce MFA on certain search APIs, which allows authenticated attackers to bypass MFA protections via user search, channel search, or team search queries.
6.5
Medium
CVE-2025-25274 2025-03-21 08h24 +00:00 Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to restrict command execution in archived channels, which allows authenticated users to run commands in archived channels.
8.8
High
CVE-2025-27933 2025-03-21 08h23 +00:00 Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to fail to enforce channel conversion restrictions, which allows members with permission to convert public channels to private ones to also convert private ones to public
5.4
Medium