Low severityNVD Advisory· Published Jan 9, 2025· Updated Jan 9, 2025
Misleading UI for undefined admin console settings in Calls causes security confusion
CVE-2025-22445
Description
Mattermost versions 10.x <= 10.2 fail to accurately reflect missing settings, which allows confusion for admins regarding a Calls security-sensitive configuration via incorrect UI reporting.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/mattermost/mattermost/server/v8Go | >= 10.0, < 10.3.0 | 10.3.0 |
github.com/mattermost/mattermost/server/v8Go | < 8.0.0-20250102081831-64c566a8280b | 8.0.0-20250102081831-64c566a8280b |
Affected products
1- Range: 10.0.*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/advisories/GHSA-7rgp-4j56-fm79ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-22445ghsaADVISORY
- mattermost.com/security-updatesghsaWEB
News mentions
0No linked articles in our index yet.