Логотип exploitDog
bind:CVE-2025-3230
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-3230

Количество 3

Количество 3

nvd логотип

CVE-2025-3230

8 месяцев назад

Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly invalidate personal access tokens upon user deactivation, allowing deactivated users to maintain full system access by exploiting access token validation flaws via continued usage of previously issued tokens.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2025-3230

8 месяцев назад

Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5 ...

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-mc2f-jgj6-6cp3

8 месяцев назад

Mattermost fails to properly invalidate personal access tokens upon user deactivation

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-3230

Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly invalidate personal access tokens upon user deactivation, allowing deactivated users to maintain full system access by exploiting access token validation flaws via continued usage of previously issued tokens.

CVSS3: 5.4
0%
Низкий
8 месяцев назад
debian логотип
CVE-2025-3230

Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5 ...

CVSS3: 5.4
0%
Низкий
8 месяцев назад
github логотип
GHSA-mc2f-jgj6-6cp3

Mattermost fails to properly invalidate personal access tokens upon user deactivation

CVSS3: 5.4
0%
Низкий
8 месяцев назад

Уязвимостей на страницу