VYPR
Moderate severityNVD Advisory· Published Mar 21, 2025· Updated Mar 21, 2025

Unauthorized Private-to-Public Channel Conversion

CVE-2025-27933

Description

Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to fail to enforce channel conversion restrictions, which allows members with permission to convert public channels to private ones to also convert private ones to public

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/mattermost/mattermost/server/v8Go
>= 10.4.0, < 10.4.310.4.3
github.com/mattermost/mattermost/server/v8Go
>= 10.3.0, < 10.3.410.3.4
github.com/mattermost/mattermost/server/v8Go
>= 9.11.0, < 9.11.99.11.9
github.com/mattermost/mattermost-serverGo
< 9.11.99.11.9
github.com/mattermost/mattermost/server/v8Go
< 8.0.0-20250218135018-e644e3c8e3938.0.0-20250218135018-e644e3c8e393

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.