Mattermost Plugins
cpe:2.3:a:mattermost:mattermost_plugins:*:*:*:*:*:*:*
- <= 11.5
- <= 11.1.5
- <= 10.13.11
- <= 11.3.4.0
A vulnerability exists in Mattermost Plugins in versions through 11.5, 11.1.5, 10.13.11, and 11.3.4.0, where the plugins fail to properly validate namespaces. This flaw enables plugin users to subscribe to groups that are not whitelisted by creating groups with prefixes that match those of whitelisted groups.
Exploitation of this vulnerability could lead to unauthorized group subscriptions, potentially allowing users to access or interact with unapproved group content or activities.
Users can upgrade to Mattermost Plugins version 11.7 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.