Описание
Mattermost versions 9.11.x <= 9.11.5 fail to enforce invite permissions, which allows team admins, with no permission to invite users to their team, to invite users by updating the "allow_open_invite" field via making their team public.
Ссылки
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 9.11.0 (включая) до 9.11.6 (исключая)
cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
EPSS
Процентиль: 29%
0.001
Низкий
3.8 Low
CVSS3
Дефекты
CWE-863
Связанные уязвимости
CVSS3: 3.8
redhat
12 месяцев назад
Mattermost versions 9.11.x <= 9.11.5 fail to enforce invite permissions, which allows team admins, with no permission to invite users to their team, to invite users by updating the "allow_open_invite" field via making their team public.
CVSS3: 3.8
debian
12 месяцев назад
Mattermost versions 9.11.x <= 9.11.5 fail to enforce invite permission ...
EPSS
Процентиль: 29%
0.001
Низкий
3.8 Low
CVSS3
Дефекты
CWE-863