CVE-2023-1774

MEDIUM5.4EPSS 0.16%

Mattermost fails to properly authentication inviter's permissions to private channel

發布日:2023/3/31修改日:2025/4/3

描述

When processing an email invite to a private channel on a team, Mattermost fails to validate the inviter's permission to that channel, allowing an attacker to invite themselves to a private channel.

受影響套件(4)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM5.4CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

參考連結(4)