Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3vcm-c42p-3hhf

Опубликовано: 15 сент. 2025
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Mattermost Missing Authorization vulnerability

Mattermost versions 10.10.x <= 10.10.1 fail to properly sanitize user data during shared channel membership synchronization, which allows malicious or compromised remote clusters to access sensitive user information via unsanitized user objects. This vulnerability affects Mattermost Server instances with shared channels enabled.

Пакеты

Наименование

github.com/mattermost/mattermost/server/v8

go
Затронутые версииВерсия исправления

< 8.0.0-20250729073403-517ae758cd02

8.0.0-20250729073403-517ae758cd02

Наименование

github.com/mattermost/mattermost-server

go
Затронутые версииВерсия исправления

>= 10.10.0, < 10.10.2

10.10.2

EPSS

Процентиль: 15%
0.0005
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 6.5
nvd
5 месяцев назад

Mattermost versions 10.10.x <= 10.10.1 fail to properly sanitize user data during shared channel membership synchronization, which allows malicious or compromised remote clusters to access sensitive user information via unsanitized user objects. This vulnerability affects Mattermost Server instances with shared channels enabled.

CVSS3: 6.5
debian
5 месяцев назад

Mattermost versions 10.10.x <= 10.10.1 fail to properly sanitize user ...

EPSS

Процентиль: 15%
0.0005
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-862