CVE-2025-30179

MEDIUM4.3EPSS 0.09%

Mattermost Fails to Enforce Certain Search APIs

發布日:2025/3/21修改日:2025/3/28
也稱為:GHSA-3gpx-p63p-pr5rBIT-mattermost-2025-30179GO-2025-3549

描述

Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to enforce MFA on certain search APIs, which allows authenticated attackers to bypass MFA protections via user search, channel search, or team search queries.

受影響套件(6)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM4.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

參考連結(4)