Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-22449

Опубликовано: 09 янв. 2025
Источник: redhat
CVSS3: 3.8
EPSS Низкий

Описание

Mattermost versions 9.11.x <= 9.11.5 fail to enforce invite permissions, which allows team admins, with no permission to invite users to their team, to invite users by updating the "allow_open_invite" field via making their team public.

A flaw was found in Mattermost. In certain versions, Mattermost fails to enforce invite permissions, which allows team admins with no permissions to invite users to their team by updating the "allow_open_invite" field via making their team public.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/acm-grafana-rhel8Not affected
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-central-db-rhel8Not affected
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-main-rhel8Not affected
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-rhel8-operatorNot affected
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-roxctl-rhel8Not affected
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-scanner-v4-db-rhel8Not affected
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-scanner-v4-rhel8Not affected
Red Hat Ceph Storage 5rhceph/rhceph-5-dashboard-rhel8Not affected
Red Hat Ceph Storage 6rhceph/rhceph-6-dashboard-rhel9Not affected
Red Hat Ceph Storage 8rhceph/grafana-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-863
https://bugzilla.redhat.com/show_bug.cgi?id=2336638mattermost: Access control flaw for team admins allows unauthorized team additions

EPSS

Процентиль: 20%
0.00278
Низкий

3.8 Low

CVSS3

Связанные уязвимости

CVSS3: 3.8
nvd
больше 1 года назад

Mattermost versions 9.11.x <= 9.11.5 fail to enforce invite permissions, which allows team admins, with no permission to invite users to their team, to invite users by updating the "allow_open_invite" field via making their team public.

CVSS3: 3.8
debian
больше 1 года назад

Mattermost versions 9.11.x <= 9.11.5 fail to enforce invite permission ...

CVSS3: 3.8
github
больше 1 года назад

Mattermost Incorrect Authorization vulnerability

EPSS

Процентиль: 20%
0.00278
Низкий

3.8 Low

CVSS3