Логотип exploitDog
bind:CVE-2025-3611
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-3611

Количество 3

Количество 3

nvd логотип

CVE-2025-3611

8 месяцев назад

Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly enforce access control restrictions for System Manager roles, allowing authenticated users with System Manager privileges to view team details they should not have access to via direct API requests to team endpoints, even when explicitly configured with 'No access' to Teams in the System Console.

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2025-3611

8 месяцев назад

Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11 ...

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-86jg-35xj-3vv5

8 месяцев назад

Mattermost fails to properly enforce access control restrictions for System Manager roles

CVSS3: 3.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-3611

Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly enforce access control restrictions for System Manager roles, allowing authenticated users with System Manager privileges to view team details they should not have access to via direct API requests to team endpoints, even when explicitly configured with 'No access' to Teams in the System Console.

CVSS3: 3.1
0%
Низкий
8 месяцев назад
debian логотип
CVE-2025-3611

Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11 ...

CVSS3: 3.1
0%
Низкий
8 месяцев назад
github логотип
GHSA-86jg-35xj-3vv5

Mattermost fails to properly enforce access control restrictions for System Manager roles

CVSS3: 3.1
0%
Низкий
8 месяцев назад

Уязвимостей на страницу