Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4v7j-4mvr-5975

Опубликовано: 13 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5.9

Описание

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to invalidate OAuth refresh tokens upon user account deactivation, which allows a deactivated user or an attacker in possession of a valid refresh token to obtain new functional access tokens via the OAuth refresh token grant endpoint.. Mattermost Advisory ID: MMSA-2026-00680

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to invalidate OAuth refresh tokens upon user account deactivation, which allows a deactivated user or an attacker in possession of a valid refresh token to obtain new functional access tokens via the OAuth refresh token grant endpoint.. Mattermost Advisory ID: MMSA-2026-00680

EPSS

Процентиль: 7%
0.00174
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-305

EPSS

Процентиль: 7%
0.00174
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-305