Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hw87-6jcq-9f8q

Опубликовано: 15 мая 2026
Источник: github
Github: Прошло ревью
CVSS3: 3.1

Описание

Mattermost doesn't enforce the PostEditTimeLimit on non-message post fields

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to enforce the PostEditTimeLimit on non-message post fields which allows an authenticated user to modify post file attachments, props, and pin status after the edit window has expired via the post patch and update API endpoints. Mattermost Advisory ID: MMSA-2026-00631.

Пакеты

Наименование

github.com/mattermost/mattermost-server

go
Затронутые версииВерсия исправления

>= 11.5.0, < 11.5.2

11.5.2

Наименование

github.com/mattermost/mattermost-server

go
Затронутые версииВерсия исправления

>= 0.0.0-20250731163400-5b955468ea1e, < 0.0.0-20260414103857-b21ef302025e

0.0.0-20260414103857-b21ef302025e

EPSS

Процентиль: 6%
0.00165
Низкий

3.1 Low

CVSS3

Дефекты

CWE-672

Связанные уязвимости

CVSS3: 3.1
nvd
3 месяца назад

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to enforce the PostEditTimeLimit on non-message post fields which allows an authenticated user to modify post file attachments, props, and pin status after the edit window has expired via the post patch and update API endpoints.. Mattermost Advisory ID: MMSA-2026-00631

CVSS3: 3.1
debian
3 месяца назад

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to enfo ...

EPSS

Процентиль: 6%
0.00165
Низкий

3.1 Low

CVSS3

Дефекты

CWE-672