CVE-2025-14350

MEDIUM4.3EPSS 0.04%

Mattermost fails to properly validate team membership when processing channel mentions

發布日:2026/2/16修改日:2026/4/1
也稱為:GHSA-57cc-2pf4-mhmxGO-2026-4521

描述

Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to properly validate team membership when processing channel mentions which allows authenticated users to determine the existence of teams and their URL names via posting channel shortlinks and observing the channel_mentions property in the API response. Mattermost Advisory ID: MMSA-2025-00563

受影響套件(6)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM4.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

參考連結(5)