- Description
- Mattermost versions 9.11.x <= 9.11.6, 10.4.x <= 10.4.1 fail to invalidate all active sessions when converting a user to a bot, with allows the converted user to escalate their privileges depending on the permissions granted to the bot.
- Source
- responsibledisclosure@mattermost.com
- NVD status
- Analyzed
- Products
- mattermost_server
CVSS 3.1
- Type
- Primary
- Base score
- 8.8
- Impact score
- 5.9
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
- responsibledisclosure@mattermost.com
- CWE-384
- Hype score
- Not currently trending
- CVE-2025-1412 Privilege Escalation in Mattermost via Incomplete Session Invalidation https://t.co/30YqNHx97k - @VulmonFeeds - 24 Feb 2025 - 44 Impressions - 0 Retweets - 0 Likes - 0 Bookmarks - 0 Replies - 0 Quotes 
- CVE-2025-1412 Mattermost versions 9.11.x <= 9.11.6, 10.4.x <= 10.4.1 fail to invalidate all active sessions when converting a user to a bot, with allows the converted user to escalat… https://t.co/pToC3jjW0g - @CVEnew - 24 Feb 2025 - 483 Impressions - 0 Retweets - 0 Likes - 0 Bookmarks - 0 Replies - 0 Quotes 
[
  {
    "nodes": [
      {
        "negate": false,
        "cpeMatch": [
          {
            "criteria": "cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*",
            "vulnerable": true,
            "matchCriteriaId": "DA9C4D79-7816-45EA-9F2D-B49965DED6B4",
            "versionEndExcluding": "9.11.7",
            "versionStartIncluding": "9.11.0"
          },
          {
            "criteria": "cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*",
            "vulnerable": true,
            "matchCriteriaId": "20456526-878A-4CEA-A563-0D9878ED300C",
            "versionEndExcluding": "10.4.2",
            "versionStartIncluding": "10.4.0"
          }
        ],
        "operator": "OR"
      }
    ]
  }
]