Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qvqh-cmq6-xvfq

Опубликовано: 13 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 3.8

Описание

Mattermost versions 11.7.x <= 11.7.2, 10.11.x <= 10.11.19 fail to sanitize team objects returned by the scheme teams endpoint, which allows a user with the User Manager role to obtain invite links for private teams and use them to join or share access to those teams via the scheme teams API endpoint.. Mattermost Advisory ID: MMSA-2026-00671

Mattermost versions 11.7.x <= 11.7.2, 10.11.x <= 10.11.19 fail to sanitize team objects returned by the scheme teams endpoint, which allows a user with the User Manager role to obtain invite links for private teams and use them to join or share access to those teams via the scheme teams API endpoint.. Mattermost Advisory ID: MMSA-2026-00671

EPSS

Процентиль: 5%
0.00152
Низкий

3.8 Low

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 3.8
nvd
18 дней назад

Mattermost versions 11.7.x <= 11.7.2, 10.11.x <= 10.11.19 fail to sanitize team objects returned by the scheme teams endpoint, which allows a user with the User Manager role to obtain invite links for private teams and use them to join or share access to those teams via the scheme teams API endpoint.. Mattermost Advisory ID: MMSA-2026-00671

CVSS3: 3.8
debian
18 дней назад

Mattermost versions 11.7.x <= 11.7.2, 10.11.x <= 10.11.19 fail to sani ...

EPSS

Процентиль: 5%
0.00152
Низкий

3.8 Low

CVSS3

Дефекты

CWE-862