Mattermost
cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*
- >= 10.11, <= 10.11.5
- >= 11.0, <= 11.0.4
- >= 10.12, <= 10.12.2
A vulnerability exists in Mattermost versions 10.11.x prior to 10.11.5, 11.0.x prior to 11.0.4, and 10.12.x prior to 10.12.2. These versions fail to invalidate invite tokens after they have been used, which can allow malicious actors who have intercepted these tokens to manipulate channel memberships. This includes the ability to add or remove users from private channels by replaying the tokens.
Exploitation of this vulnerability could lead to unauthorized manipulation of channel memberships, allowing for the addition or removal of users from private channels.
Users can upgrade to Mattermost versions 11.1.0, 11.1.4, or 10.12.3 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.