Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-22445

Опубликовано: 09 янв. 2025
Источник: redhat
CVSS3: 3.5
EPSS Низкий

Описание

Mattermost versions 10.x <= 10.2 fail to accurately reflect missing settings, which allows confusion for admins regarding a Calls security-sensitive configuration via incorrect UI reporting.

A flaw was found in Mattermost. In certain versions, Mattermost fails to accurately reflect missing settings, which allows confusion for admins regarding a Calls security-sensitive configuration via incorrect UI reporting.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/acm-grafana-rhel8Not affected
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-central-db-rhel8Not affected
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-main-rhel8Not affected
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-rhel8-operatorNot affected
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-roxctl-rhel8Not affected
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-scanner-v4-db-rhel8Not affected
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-scanner-v4-rhel8Not affected
Red Hat Ceph Storage 5rhceph/rhceph-5-dashboard-rhel8Not affected
Red Hat Ceph Storage 6rhceph/rhceph-6-dashboard-rhel9Not affected
Red Hat Ceph Storage 8rhceph/grafana-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-754
https://bugzilla.redhat.com/show_bug.cgi?id=2336671mattermost: Misleading UI for undefined admin console settings in Calls causes security confusion

EPSS

Процентиль: 31%
0.00116
Низкий

3.5 Low

CVSS3

Связанные уязвимости

CVSS3: 3.5
nvd
12 месяцев назад

Mattermost versions 10.x <= 10.2 fail to accurately reflect missing settings, which allows confusion for admins regarding a Calls security-sensitive configuration via incorrect UI reporting.

CVSS3: 3.5
debian
12 месяцев назад

Mattermost versions 10.x <= 10.2 fail to accurately reflect missing se ...

CVSS3: 3.5
github
12 месяцев назад

Mattermost has Improper Check for Unusual or Exceptional Conditions

suse-cvrf
11 месяцев назад

Security update for govulncheck-vulndb

EPSS

Процентиль: 31%
0.00116
Низкий

3.5 Low

CVSS3