GHSA-3x39-62h4-f8j6

Suggest an improvement
Source
https://github.com/advisories/GHSA-3x39-62h4-f8j6
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/11/GHSA-3x39-62h4-f8j6/GHSA-3x39-62h4-f8j6.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-3x39-62h4-f8j6
Aliases
  • CVE-2025-12419
Published
2025-11-27T18:30:25Z
Modified
2025-12-02T01:58:38.392346Z
Severity
  • 9.9 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication
Details

Mattermost versions 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12, 11.0.x <= 11.0.3 fail to properly validate OAuth state tokens during OpenID Connect authentication which allows an authenticated attacker with team creation privileges to take over a user account via manipulation of authentication data during the OAuth completion flow. This requires email verification to be disabled (default: disabled), OAuth/OpenID Connect to be enabled, and the attacker to control two users in the SSO system with one of them never having logged into Mattermost.

Database specific
{
    "severity": "CRITICAL",
    "github_reviewed": true,
    "github_reviewed_at": "2025-12-01T23:56:55Z",
    "nvd_published_at": "2025-11-27T16:15:46Z",
    "cwe_ids": [
        "CWE-287",
        "CWE-303"
    ]
}
References

Affected packages

Go

github.com/mattermost/mattermost/server/v8

Package

Name
github.com/mattermost/mattermost/server/v8
View open source insights on deps.dev
Purl
pkg:golang/github.com/mattermost/mattermost/server/v8

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
8.0.0-20251028000919-d3ed703dc833

github.com/mattermost/mattermost-server

Package

Name
github.com/mattermost/mattermost-server
View open source insights on deps.dev
Purl
pkg:golang/github.com/mattermost/mattermost-server

Affected ranges

Type
SEMVER
Events
Introduced
10.12.0
Fixed
10.12.2

github.com/mattermost/mattermost-server

Package

Name
github.com/mattermost/mattermost-server
View open source insights on deps.dev
Purl
pkg:golang/github.com/mattermost/mattermost-server

Affected ranges

Type
SEMVER
Events
Introduced
10.11.0
Fixed
10.11.5

github.com/mattermost/mattermost-server

Package

Name
github.com/mattermost/mattermost-server
View open source insights on deps.dev
Purl
pkg:golang/github.com/mattermost/mattermost-server

Affected ranges

Type
SEMVER
Events
Introduced
10.5.0
Fixed
10.5.13

github.com/mattermost/mattermost-server

Package

Name
github.com/mattermost/mattermost-server
View open source insights on deps.dev
Purl
pkg:golang/github.com/mattermost/mattermost-server

Affected ranges

Type
SEMVER
Events
Introduced
11.0.0
Fixed
11.0.4