Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fprx-ppqr-8wgf

Опубликовано: 16 мар. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 6.6

Описание

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to restrict plugin installation on CI test instances with default admin credentials which allows an unauthenticated attacker to achieve remote code execution and exfiltrate sensitive configuration data including AWS and SMTP credentials via uploading a malicious plugin after changing the import directory. Mattermost Advisory ID: MMSA-2025-00528

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to restrict plugin installation on CI test instances with default admin credentials which allows an unauthenticated attacker to achieve remote code execution and exfiltrate sensitive configuration data including AWS and SMTP credentials via uploading a malicious plugin after changing the import directory. Mattermost Advisory ID: MMSA-2025-00528

EPSS

Процентиль: 39%
0.00179
Низкий

6.6 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 6.6
nvd
17 дней назад

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to restrict plugin installation on CI test instances with default admin credentials which allows an unauthenticated attacker to achieve remote code execution and exfiltrate sensitive configuration data including AWS and SMTP credentials via uploading a malicious plugin after changing the import directory. Mattermost Advisory ID: MMSA-2025-00528

CVSS3: 6.6
debian
17 дней назад

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10. ...

EPSS

Процентиль: 39%
0.00179
Низкий

6.6 Medium

CVSS3

Дефекты

CWE-863