216.73.216.233

CVE-2025-12419

· Published 27/11/2025 16:15 · Modified 03/12/2025 15:17

Labels: CVE-2025-12419 2025-11-27CVE-2025-12419CWE-303[email protected]

Essential information

Published
27/11/2025 16:15
Modified
03/12/2025 15:17
Author
Creator
CVSS
9.9 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CVSS metrics

Description

Mattermost versions 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12, 11.0.x <= 11.0.3 fail to properly validate OAuth state tokens during OpenID Connect authentication which allows an authenticated attacker with team creation privileges to take over a user account via manipulation of authentication data during the OAuth completion flow. This requires email verification to be disabled (default: disabled), OAuth/OpenID Connect to be enabled, and the attacker to control two users in the SSO system with one of them never having logged into Mattermost.

NVD status

Status
Analyzed — CVE has had analysis completed and all data associations made.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
mattermost / mattermost server cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
mattermost / mattermost server cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
mattermost / mattermost server cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
mattermost / mattermost server cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*

References