Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2phx-frhf-xr55

Опубликовано: 16 фев. 2026
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Mattermost Plugin Zoom allows any logged-in user to change Zoom meeting restrictions for arbitrary channels

Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 and Mattermost Plugin Zoom versions <=1.11.0 fail to validate the authenticated user when processing {{/plugins/zoom/api/v1/channel-preference}}, which allows any logged-in user to change Zoom meeting restrictions for arbitrary channels via crafted API requests.. Mattermost Advisory ID: MMSA-2025-00558

Пакеты

Наименование

github.com/mattermost/mattermost-plugin-zoom

go
Затронутые версииВерсия исправления

< 1.11.0

1.11.0

EPSS

Процентиль: 11%
0.00036
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 4.3
nvd
около 2 месяцев назад

Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 and Mattermost Plugin Zoom versions <=1.11.0 fail to validate the authenticated user when processing {{/plugins/zoom/api/v1/channel-preference}}, which allows any logged-in user to change Zoom meeting restrictions for arbitrary channels via crafted API requests.. Mattermost Advisory ID: MMSA-2025-00558

CVSS3: 4.3
debian
около 2 месяцев назад

Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11 ...

EPSS

Процентиль: 11%
0.00036
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-863