Mattermost Desktop App versions <6.0.0 fail to sanitize sensitive information from Mattermost logs and clear data on server deletion which allows an attacker with access to the users system to gain access to potentially sensitive information via reading the application logs.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
Wed, 17 Dec 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mattermost Desktop App versions <6.0.0 fail to sanitize sensitive information from Mattermost logs and clear data on server deletion which allows an attacker with access to the users system to gain access to potentially sensitive information via reading the application logs. | |
| Title | Mattermost Desktop App logging sensitive information and fails to clear data on server deletion | |
| Weaknesses | CWE-532 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2025-12-17T19:29:49.378Z
Reserved: 2025-11-17T15:51:49.044Z
Link: CVE-2025-13321
No data.
Status : Received
Published: 2025-12-17T19:16:00.927
Modified: 2025-12-17T19:16:00.927
Link: CVE-2025-13321
No data.
OpenCVE Enrichment
No data.