Количество 3
Количество 3
CVE-2026-6333
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to validate the Host header when constructing response URLs for custom slash commands which allows an authenticated attacker to redirect slash command responses to an attacker-controlled server via a spoofed Host header.. Mattermost Advisory ID: MMSA-2026-00582
CVE-2026-6333
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to vali ...
GHSA-vqp5-2mrp-qqxg
Mattermost doesn't validate the Host header when constructing response URLs for custom slash command
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-6333 Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to validate the Host header when constructing response URLs for custom slash commands which allows an authenticated attacker to redirect slash command responses to an attacker-controlled server via a spoofed Host header.. Mattermost Advisory ID: MMSA-2026-00582 | CVSS3: 3.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-6333 Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to vali ... | CVSS3: 3.5 | 0% Низкий | 3 месяца назад | |
GHSA-vqp5-2mrp-qqxg Mattermost doesn't validate the Host header when constructing response URLs for custom slash command | CVSS3: 3.5 | 0% Низкий | 3 месяца назад |
Уязвимостей на страницу