Описание
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to validate that the RefreshedToken differs from the original invite token during remote cluster invite confirmation which allows an authenticated attacker to bypass token rotation and reuse the original invite token via sending a crafted invite confirmation with a RefreshedToken matching the original token. Mattermost Advisory ID: MMSA-2026-00575
Ссылки
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 10.11.0 (включая) до 10.11.14 (исключая)Версия от 11.5.0 (включая) до 11.5.2 (исключая)
Одно из
cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
EPSS
Процентиль: 4%
0.00142
Низкий
3.7 Low
CVSS3
4.3 Medium
CVSS3
Дефекты
CWE-863
Связанные уязвимости
CVSS3: 3.7
debian
3 месяца назад
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to vali ...
CVSS3: 3.7
github
3 месяца назад
Mattermost doesn't validate that the RefreshedToken differs from the original invite token during remote cluster invite confirmation
EPSS
Процентиль: 4%
0.00142
Низкий
3.7 Low
CVSS3
4.3 Medium
CVSS3
Дефекты
CWE-863