Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to properly validate permissions for the API endpoint /plugins/playbooks/api/v0/signal/keywords/ignore-thread, allowing any user or attacker to delete posts containing actions created by the Playbooks bot, even without channel access or appropriate permissions.
References
History

Thu, 24 Apr 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 24 Apr 2025 07:00:00 +0000

Type Values Removed Values Added
Description Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to properly validate permissions for the API endpoint /plugins/playbooks/api/v0/signal/keywords/ignore-thread, allowing any user or attacker to delete posts containing actions created by the Playbooks bot, even without channel access or appropriate permissions.
Title Unauthorized Playbooks Post Deletion in Mattermost Playbooks Plugin
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published: 2025-04-24T06:50:12.214Z

Updated: 2025-04-24T13:06:53.385Z

Reserved: 2025-04-22T11:38:20.780Z

Link: CVE-2025-41423

cve-icon Vulnrichment

Updated: 2025-04-24T13:04:00.926Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-24T07:15:31.740

Modified: 2025-04-29T13:52:47.470

Link: CVE-2025-41423

cve-icon Redhat

No data.