Security Advisory

CVE-2025-1412

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-02-24 07:24:47
Last updated 2025-02-24 11:23:35
Assigner Mattermost
CVSS score 3.1
State PUBLISHED

Description

Mattermost versions 9.11.x <= 9.11.6, 10.4.x <= 10.4.1 fail to invalidate all active sessions when converting a user to a bot, with allows the converted user to escalate their privileges depending on the permissions granted to the bot.