Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-22449

Опубликовано: 09 янв. 2025
Источник: redhat
CVSS3: 3.8

Описание

Mattermost versions 9.11.x <= 9.11.5 fail to enforce invite permissions, which allows team admins, with no permission to invite users to their team, to invite users by updating the "allow_open_invite" field via making their team public.

A flaw was found in Mattermost. In certain versions, Mattermost fails to enforce invite permissions, which allows team admins with no permissions to invite users to their team by updating the "allow_open_invite" field via making their team public.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/acm-grafana-rhel8Not affected
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-central-db-rhel8Not affected
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-main-rhel8Not affected
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-rhel8-operatorNot affected
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-roxctl-rhel8Not affected
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-scanner-v4-db-rhel8Not affected
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-scanner-v4-rhel8Not affected
Red Hat Ceph Storage 5rhceph/rhceph-5-dashboard-rhel8Not affected
Red Hat Ceph Storage 6rhceph/rhceph-6-dashboard-rhel9Not affected
Red Hat Ceph Storage 8rhceph/grafana-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-863
https://bugzilla.redhat.com/show_bug.cgi?id=2336638mattermost: Access control flaw for team admins allows unauthorized team additions

3.8 Low

CVSS3

Связанные уязвимости

CVSS3: 3.8
nvd
около 1 года назад

Mattermost versions 9.11.x <= 9.11.5 fail to enforce invite permissions, which allows team admins, with no permission to invite users to their team, to invite users by updating the "allow_open_invite" field via making their team public.

CVSS3: 3.8
debian
около 1 года назад

Mattermost versions 9.11.x <= 9.11.5 fail to enforce invite permission ...

CVSS3: 3.8
github
около 1 года назад

Mattermost Incorrect Authorization vulnerability

suse-cvrf
около 1 года назад

Security update for govulncheck-vulndb

3.8 Low

CVSS3