Описание
Mattermost versions 9.11.x <= 9.11.5 fail to enforce invite permissions, which allows team admins, with no permission to invite users to their team, to invite users by updating the "allow_open_invite" field via making their team public.
Ссылки
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 9.11.0 (включая) до 9.11.6 (исключая)
cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
EPSS
Процентиль: 28%
0.001
Низкий
3.8 Low
CVSS3
Дефекты
CWE-863
Связанные уязвимости
CVSS3: 3.8
redhat
около 1 года назад
Mattermost versions 9.11.x <= 9.11.5 fail to enforce invite permissions, which allows team admins, with no permission to invite users to their team, to invite users by updating the "allow_open_invite" field via making their team public.
CVSS3: 3.8
debian
около 1 года назад
Mattermost versions 9.11.x <= 9.11.5 fail to enforce invite permission ...
CVSS3: 3.8
github
около 1 года назад
Mattermost Incorrect Authorization vulnerability
EPSS
Процентиль: 28%
0.001
Низкий
3.8 Low
CVSS3
Дефекты
CWE-863