Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to clear Google OAuth credentials when converting user accounts to bot accounts, allowing attackers to gain unauthorized access to bot accounts via the Google OAuth signup flow.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://mattermost.com/security-updates |
![]() ![]() |
History
Fri, 30 May 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 30 May 2025 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to clear Google OAuth credentials when converting user accounts to bot accounts, allowing attackers to gain unauthorized access to bot accounts via the Google OAuth signup flow. | |
Title | Google OAuth Authentication Bypass for Converted Bot Accounts | |
Weaknesses | CWE-303 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Mattermost
Published: 2025-05-30T14:22:08.913Z
Updated: 2025-05-30T14:44:40.129Z
Reserved: 2025-03-20T20:10:48.601Z
Link: CVE-2025-2571

Updated: 2025-05-30T14:44:30.858Z

Status : Awaiting Analysis
Published: 2025-05-30T15:15:40.873
Modified: 2025-05-30T16:31:03.107
Link: CVE-2025-2571

No data.