Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fg35-5rf6-qg3g

Опубликовано: 25 мар. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5.7

Описание

Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to properly validate user identity in the OpenID {{IsSameUser()}} comparison logic, which allows an attacker to take over arbitrary user accounts via an overly permissive substring matching flaw in the user discovery flow.. Mattermost Advisory ID: MMSA-2026-00590

Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to properly validate user identity in the OpenID {{IsSameUser()}} comparison logic, which allows an attacker to take over arbitrary user accounts via an overly permissive substring matching flaw in the user discovery flow.. Mattermost Advisory ID: MMSA-2026-00590

EPSS

Процентиль: 8%
0.00027
Низкий

5.7 Medium

CVSS3

Дефекты

CWE-303

Связанные уязвимости

CVSS3: 5.7
nvd
6 дней назад

Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to properly validate user identity in the OpenID {{IsSameUser()}} comparison logic, which allows an attacker to take over arbitrary user accounts via an overly permissive substring matching flaw in the user discovery flow.. Mattermost Advisory ID: MMSA-2026-00590

CVSS3: 5.7
debian
6 дней назад

Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2 ...

EPSS

Процентиль: 8%
0.00027
Низкий

5.7 Medium

CVSS3

Дефекты

CWE-303