← voltar
CVE-2025-13324

Lack of Invalidation of Legacy Remote Cluster Invite Tokens After Confirmation

CVSS 3.7 LOWEPSS 0.2%CWE-863
Vexday Risk Score
8Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 3.7EPSS 0.2%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
17 dez 2025Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
Mattermost versions 10.11.x <= 10.11.5, 11.0.x <= 11.0.4, 10.12.x <= 10.12.2 fail to invalidate remote cluster invite tokens when using the legacy (version 1) protocol or when the confirming party does not provide a refreshed token, which allows an attacker who has obtained an invite token to authenticate as the remote cluster and perform limited actions on shared channels even after the invitation has been legitimately confirmed.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Produtos afetados
Mattermost · Mattermost

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →