← Späť na vyhľadávanie CVE

CVE-2026-28735

Mattermost

Popis

Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate the OAuth token scope on the callback which allows an authenticated Mattermost user to gain access to private repositories via modifying the scope parameter in the GitHub authorization URL.. Mattermost Advisory ID: MMSA-2026-00628

CVSS 5.4EPSS 0.13799999999999998%Riziko 0.55
Zobraziť zdroj
Zverejnené
2026-05-22 17:16:46
Dotknuté verzie
<= 11.6.0, <= 11.5.3, <= 11.4.4, <= 10.11.14
Typ
Webová aplikácia
Vektor
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N