CVE-2025-2475

MEDIUM5.4EPSS 0.14%

Mattermost vulnerable to Incorrect Implementation of Authentication Algorithm

發布日:2025/4/14修改日:2026/2/4
也稱為:GHSA-6rqh-8465-2xcwCGA-8x8q-42mh-55c2GO-2025-3610

描述

Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to invalidate the cache when a user account is converted to a bot which allows an attacker to login to the bot exactly one time via normal credentials.

受影響套件(5)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM5.4CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

參考連結(10)