CVE-2025-30179

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Mar 21, 2025
Updated: Mar 27, 2025
CWE ID 863

Summary

CVE-2025-30179 is a vulnerability affecting Mattermost versions 10.4.x up to 10.4.2, 10.3.x up to 10.3.3, and 9.11.x up to 9.11.8. This issue allows authenticated attackers to bypass Multi-Factor Authentication (MFA) protections by exploiting a flaw in certain search APIs. Attackers can carry out user searches, channel searches, or team searches without being prompted for additional verification codes, putting sensitive information at risk. This vulnerability highlights the importance of keeping Mattermost installations updated to ensure the latest security patches are applied.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Mattermost Server

Affected Vendors

  • Mattermost, Inc.