Mattermost Server 10.5.9 Release Candidate 1

CPE Details

Mattermost Server 10.5.9 Release Candidate 1
10.5.9
2025-07-03
15h48 +00:00
2025-07-03
15h48 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:mattermost:mattermost_server:10.5.9:rc1:*:*:*:*:*:*

Informations

Vendor

mattermost

Product

mattermost_server

Version

10.5.9

Update

rc1

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2025-9072 2025-09-15 10h28 +00:00 Mattermost versions 10.10.x <= 10.10.1, 10.5.x <= 10.5.9, 10.9.x <= 10.9.4 fail to validate the redirect_to parameter, allowing an attacker to craft a malicious link that, once a user authenticates with their SAML provider, could post the user’s cookies to an attacker-controlled URL.
7.6
High
CVE-2025-9084 2025-09-15 10h22 +00:00 Mattermost versions 10.5.x <= 10.5.9 fail to properly validate redirect URLs which allows attackers to redirect users to malicious sites via crafted OAuth login URLs
6.1
Medium