Описание
Mattermost versions 11.8.x <= 11.8.2, 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to restrict channel member role assignment to channel-scoped roles which allows a channel administrator to gain additional channel permissions via the channel member roles API.. Mattermost Advisory ID: MMSA-2026-00697
EPSS
Процентиль: 5%
0.00154
Низкий
6.3 Medium
CVSS3
Дефекты
CWE-863
Связанные уязвимости
CVSS3: 6.3
debian
6 дней назад
Mattermost versions 11.8.x <= 11.8.2, 11.7.x <= 11.7.6, 10.11.x <= 10. ...
CVSS3: 6.3
github
6 дней назад
Mattermost versions 11.8.x <= 11.8.2, 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to restrict channel member role assignment to channel-scoped roles which allows a channel administrator to gain additional channel permissions via the channel member roles API.. Mattermost Advisory ID: MMSA-2026-00697
EPSS
Процентиль: 5%
0.00154
Низкий
6.3 Medium
CVSS3
Дефекты
CWE-863