216.73.217.50

CVE-2025-4573

· Published 11/06/2025 11:15 · Modified 12/06/2025 16:06

Labels: CVE-2025-4573 2025-06-11CVE-2025-4573CWE-90[email protected]

Essential information

Published
11/06/2025 11:15
Modified
12/06/2025 16:06
Author
Creator
CVSS
4.1 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N

CVSS metrics

Description

Mattermost versions 10.7.x <= 10.7.1, 10.6.x <= 10.6.3, 10.5.x <= 10.5.4, 9.11.x <= 9.11.13 fail to properly validate LDAP group ID attributes, allowing an authenticated administrator with PermissionSysconsoleWriteUserManagementGroups permission to execute LDAP search filter injection via the PUT /api/v4/ldap/groups/{remote_id}/link API when objectGUID is configured as the Group ID Attribute.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
mattermost / mattermost cpe:2.3:a:mattermost:mattermost:10.7.0-10.7.1:*:*:*:*:*:*:*
mattermost / mattermost cpe:2.3:a:mattermost:mattermost:10.6.0-10.6.3:*:*:*:*:*:*:*
mattermost / mattermost cpe:2.3:a:mattermost:mattermost:10.5.0-10.5.4:*:*:*:*:*:*:*
mattermost / mattermost cpe:2.3:a:mattermost:mattermost:9.11.0-9.11.13:*:*:*:*:*:*:*

References