CVE-2024-50052

MEDIUM4.3EPSS 0.26%

Mattermost server allows authenticated user to delete arbitrary post

發布日:2024/10/29修改日:2026/2/4
也稱為:GHSA-g376-m3h3-mj4rCGA-r988-69hx-39xgGO-2024-3235

描述

Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 fail to check that the origin of the message in an integration action matches with the original post metadata which allows an authenticated user to delete an arbitrary post.

受影響套件(5)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 4.0CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
osvCVSS 3.1MEDIUM4.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

參考連結(3)