Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8jmp-2xx6-pjg7

Опубликовано: 13 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 4.9

Описание

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate that an assigned incoming webhook user has access to the target team or channel, which allows a requester with webhook management permissions to create posts or direct messages attributed to another user via crafted incoming webhook configuration and payloads.. Mattermost Advisory ID: MMSA-2026-00683

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate that an assigned incoming webhook user has access to the target team or channel, which allows a requester with webhook management permissions to create posts or direct messages attributed to another user via crafted incoming webhook configuration and payloads.. Mattermost Advisory ID: MMSA-2026-00683

EPSS

Процентиль: 11%
0.0021
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 4.9
nvd
18 дней назад

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate that an assigned incoming webhook user has access to the target team or channel, which allows a requester with webhook management permissions to create posts or direct messages attributed to another user via crafted incoming webhook configuration and payloads.. Mattermost Advisory ID: MMSA-2026-00683

CVSS3: 4.9
debian
18 дней назад

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10. ...

EPSS

Процентиль: 11%
0.0021
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-639