Launch Week Day 1: Announcing Security Design Review
MEDIUM 4.6 Go

Improper Control of a Resource Through its Lifetime in Mattermost

GHSA-fxwj-v664-wv5g · BIT-mattermost-2022-1385 · CVE-2022-1385 · GO-2022-0599

Published · Modified

Description

Mattermost 6.4.x and earlier fails to properly invalidate pending email invitations when the action is performed from the system console, which allows accidentally invited users to join the workspace and access information from the public teams and channels.

Ready to move

Start Securing

Free, no credit card | First findings in minutes