Mattermost boards plugin fails to restrict download access to files
Low severity
GitHub Reviewed
Published
Sep 19, 2025
to the GitHub Advisory Database
•
Updated Sep 26, 2025
Package
Affected versions
< 0.0.0-20250716054606-3f3e3becfe1d
Patched versions
0.0.0-20250716054606-3f3e3becfe1d
>= 10.5.0-rc1, < 10.5.9
>= 9.11.0-rc1, < 9.11.18
10.5.9
9.11.18
< 8.0.0-20250721095935-11c36f4d1e44
8.0.0-20250721095935-11c36f4d1e44
Description
Published by the National Vulnerability Database
Sep 19, 2025
Published to the GitHub Advisory Database
Sep 19, 2025
Reviewed
Sep 22, 2025
Last updated
Sep 26, 2025
Mattermost versions 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate access controls which allows any authenticated user to download sensitive files via board file download endpoint using UUID enumeration
References