Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-1774

Опубликовано: 31 мар. 2023
Источник: debian

Описание

When processing an email invite to a private channel on a team, Mattermost fails to validate the inviter's permission to that channel, allowing an attacker to invite themselves to a private channel.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mattermost-serveritppackage

Связанные уязвимости

CVSS3: 4.2
nvd
почти 3 года назад

When processing an email invite to a private channel on a team, Mattermost fails to validate the inviter's permission to that channel, allowing an attacker to invite themselves to a private channel.

CVSS3: 5.4
github
почти 3 года назад

Mattermost fails to properly authentication inviter's permissions to private channel