Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pfw6-5rx3-xh3c

Опубликовано: 29 фев. 2024
Источник: github
Github: Прошло ревью
CVSS4: 5.3
CVSS3: 4.3

Описание

Mattermost fails to check the "invite_guest" permission

Mattermost fails to check the "invite_guest" permission when inviting guests of other teams to a team, allowing a member with permissions to add other members but not to add guests to add a guest to a team as long as the guest was already a guest in another team of the server

Пакеты

Наименование

github.com/mattermost/mattermost/server/v8

go
Затронутые версииВерсия исправления

>= 9.4.0, < 9.4.2

9.4.2

Наименование

github.com/mattermost/mattermost/server/v8

go
Затронутые версииВерсия исправления

>= 9.3.0, < 9.3.1

9.3.1

Наименование

github.com/mattermost/mattermost/server/v8

go
Затронутые версииВерсия исправления

>= 9.2.0, < 9.2.5

9.2.5

Наименование

github.com/mattermost/mattermost/server/v8

go
Затронутые версииВерсия исправления

< 8.1.9

8.1.9

EPSS

Процентиль: 30%
0.00109
Низкий

5.3 Medium

CVSS4

4.3 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 4.3
nvd
почти 2 года назад

Mattermost fails to check the "invite_guest" permission when inviting guests of other teams to a team, allowing a member with permissions to add other members but not to add guests to add a guest to a team as long as the guest was already a guest in another team of the server

CVSS3: 4.3
debian
почти 2 года назад

Mattermost fails to check the"invite_guest" permission when invitinggu ...

EPSS

Процентиль: 30%
0.00109
Низкий

5.3 Medium

CVSS4

4.3 Medium

CVSS3

Дефекты

CWE-284