Mattermost
cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*
- >= 11.5.0, <= 11.5.1
- >= 10.11.0, <= 10.11.13
A vulnerability exists in Mattermost versions 11.5.x through 11.5.1 and 10.11.x through 10.11.13, where the application fails to properly validate that the RefreshedToken is different from the original invite token during the remote cluster invite confirmation process. This flaw allows an authenticated attacker to bypass the token rotation mechanism and reuse the original invite token by sending a crafted invite confirmation that includes a RefreshedToken matching the original token.
Exploitation of this vulnerability allows for the unauthorized reuse of invite tokens, potentially leading to unauthorized access or actions within the Mattermost application.
Users can upgrade to Mattermost versions 11.7.0 or 11.6.1 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.