Описание
Mattermost allows other users to determine when users had read channels via channel member objects
Mattermost versions 10.11.x <= 10.11.3, and 10.5.x <= 10.5.11 fail to enforce access permissions on the Agents plugin which allows other users to determine when users had read channels via channel member objects.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2025-55074
- https://github.com/mattermost/mattermost/pull/33835
- https://github.com/mattermost/mattermost/pull/33905
- https://github.com/mattermost/mattermost/commit/98acefe911dd9de7edf47a7d825dd99f53141a52
- https://github.com/mattermost/mattermost/commit/ba86dfc5876b354b9d3c20ff45c08ca6f8426149
- https://github.com/mattermost/mattermost/commit/d72d437f1567ba0b639b6e4fd73bab06c51baab5
- https://github.com/advisories/GHSA-9hh7-6558-qfp2
- https://mattermost.com/security-updates
Пакеты
github.com/mattermost/mattermost-server
>= 10.11.0, < 10.11.4
10.11.4
github.com/mattermost/mattermost-server
>= 10.5.0, < 10.5.12
10.5.12
github.com/mattermost/mattermost/server/v8
< 8.0.0-20250905150616-ba86dfc5876b6
8.0.0-20250905150616-ba86dfc5876b6
Связанные уязвимости
Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11 fail to enforce access permissions on the Agents plugin which allows other users to determine when users had read channels via channel member objects
Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11 fail to enfo ...
Уязвимость приложения для обмена мгновенными сообщениями Mattermost, связанная с недостаточной защитой служебных данных, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации