Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-22449

Опубликовано: 09 янв. 2025
Источник: redhat
CVSS3: 3.8
EPSS Низкий

Описание

Mattermost versions 9.11.x <= 9.11.5 fail to enforce invite permissions, which allows team admins, with no permission to invite users to their team, to invite users by updating the "allow_open_invite" field via making their team public.

A flaw was found in Mattermost. In certain versions, Mattermost fails to enforce invite permissions, which allows team admins with no permissions to invite users to their team by updating the "allow_open_invite" field via making their team public.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/acm-grafana-rhel8Not affected
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-central-db-rhel8Not affected
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-main-rhel8Not affected
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-rhel8-operatorNot affected
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-roxctl-rhel8Not affected
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-scanner-v4-db-rhel8Not affected
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-scanner-v4-rhel8Not affected
Red Hat Ceph Storage 5rhceph/rhceph-5-dashboard-rhel8Not affected
Red Hat Ceph Storage 6rhceph/rhceph-6-dashboard-rhel9Not affected
Red Hat Ceph Storage 8rhceph/grafana-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-863
https://bugzilla.redhat.com/show_bug.cgi?id=2336638mattermost: Access control flaw for team admins allows unauthorized team additions

EPSS

Процентиль: 28%
0.001
Низкий

3.8 Low

CVSS3

Связанные уязвимости

CVSS3: 3.8
nvd
12 месяцев назад

Mattermost versions 9.11.x <= 9.11.5 fail to enforce invite permissions, which allows team admins, with no permission to invite users to their team, to invite users by updating the "allow_open_invite" field via making their team public.

CVSS3: 3.8
debian
12 месяцев назад

Mattermost versions 9.11.x <= 9.11.5 fail to enforce invite permission ...

CVSS3: 3.8
github
12 месяцев назад

Mattermost Incorrect Authorization vulnerability

suse-cvrf
11 месяцев назад

Security update for govulncheck-vulndb

EPSS

Процентиль: 28%
0.001
Низкий

3.8 Low

CVSS3