Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update Mattermost to versions 10.9.0, 10.5.6, 9.11.16, 10.8.1, 10.7.3, 10.6.6 or higher.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-18757 | Mattermost allows an unauthorized Guest user access to Playbook |
Github GHSA |
GHSA-4578-6gjh-f2jm | Mattermost allows an unauthorized Guest user access to Playbook |
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
Tue, 08 Jul 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost
Mattermost mattermost Server |
|
| CPEs | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* cpe:2.3:a:mattermost:mattermost_server:10.8.0:-:*:*:*:*:*:* cpe:2.3:a:mattermost:mattermost_server:10.8.0:rc1:*:*:*:*:*:* cpe:2.3:a:mattermost:mattermost_server:10.8.0:rc2:*:*:*:*:*:* cpe:2.3:a:mattermost:mattermost_server:10.8.0:rc3:*:*:*:*:*:* |
|
| Vendors & Products |
Mattermost
Mattermost mattermost Server |
Mon, 23 Jun 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 20 Jun 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly retrieve requestorInfo from playbooks handler for guest users which allows an attacker access to the playbook run. | |
| Title | Unauthorized Guest user access to Playbook | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2025-06-23T20:45:21.017Z
Reserved: 2025-04-03T15:36:57.160Z
Link: CVE-2025-3228
Updated: 2025-06-23T20:45:15.312Z
Status : Analyzed
Published: 2025-06-20T15:15:20.573
Modified: 2025-07-08T14:30:48.667
Link: CVE-2025-3228
No data.
OpenCVE Enrichment
Updated: 2025-06-23T08:20:14Z
EUVD
Github GHSA