Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8h9w-w78c-vvr3

Опубликовано: 18 мая 2026
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Mattermost does not verify remote cluster channel access when processing shared channel membership removals

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to validate that a remote cluster has access to a channel before processing membership removal requests during shared channel membership sync, which allows a malicious remote cluster to remove any user from any channel, including private channels, via crafted membership sync messages targeting channels the remote cluster is not authorized to access. Mattermost Advisory ID: MMSA-2026-00576.

Пакеты

Наименование

github.com/mattermost/mattermost/server/v8

go
Затронутые версииВерсия исправления

>= 11.5.0, < 11.5.2

11.5.2

Наименование

github.com/mattermost/mattermost/server/v8

go
Затронутые версииВерсия исправления

>= 10.11.0, < 10.11.14

10.11.14

Наименование

github.com/mattermost/mattermost/server/v8

go
Затронутые версииВерсия исправления

>= 11.4.0, < 11.4.4

11.4.4

Наименование

github.com/mattermost/mattermost/server/v8

go
Затронутые версииВерсия исправления

< 8.0.0-20260216150504-8738f8c4b3d4

8.0.0-20260216150504-8738f8c4b3d4

Наименование

github.com/mattermost/mattermost-server

go
Затронутые версииВерсия исправления

< 5.3.2-0.20260216150504-8738f8c4b3d4

5.3.2-0.20260216150504-8738f8c4b3d4

EPSS

Процентиль: 5%
0.00152
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 4.3
nvd
3 месяца назад

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to validate that a remote cluster has access to a channel before processing membership removal requests during shared channel membership sync, which allows a malicious remote cluster to remove any user from any channel, including private channels, via crafted membership sync messages targeting channels the remote cluster is not authorized to access. Mattermost Advisory ID: MMSA-2026-00576

CVSS3: 4.3
debian
3 месяца назад

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 1 ...

EPSS

Процентиль: 5%
0.00152
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-863