CVE-2025-13352 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

Mattermost versions 10.11.x
Low CVSS: 3.0

CVE-2025-13352

Mattermost versions 10.11.x <= 10.11.6 and Mattermost GitHub plugin versions <=2.4.0 fail to validate plugin bot identity in reaction forwarding which allows attackers to hijack the GitHub reaction feature to make users add reactions to arbitrary GitHub objects via crafted notification posts.
Vendor
Mattermost
Product
Mattermost Server
CWE
CWE-1287
Yayın Tarihi
2025-12-17 13:15:56
Güncelleme
2025-12-29 18:50:47
Source Identifier
responsibledisclosure@mattermost.com
KEV Date Added
-

Kategoriler

Referanslar