CVE-2025-20033 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

Mattermost versions 10.2.0, 9.11.x
Medium CVSS: 4.3

CVE-2025-20033

Mattermost versions 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate post types, which allows attackers to deny service to users with the sysconsole_read_plugins permission via creating a post with the custom_pl_notification type and specific props.
Vendor
Mattermost
Product
Mattermost Server
CWE
CWE-1287
Yayın Tarihi
2025-01-09 07:15:28
Güncelleme
2025-10-02 17:26:14
Source Identifier
responsibledisclosure@mattermost.com
KEV Date Added
-

Kategoriler

Referanslar