-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from improper access control when modifying team invite settings. Since the issue allows team admins without 'Add Team Members' permission to disable invites, the flaw likely exists in:
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| github.com/mattermost/mattermost/server/v8 | go | >= 9.5.0, < 9.5.8 | 9.5.8 |
| github.com/mattermost/mattermost/server/v8 | go | >= 9.10.0, < 9.10.1 | 9.10.1 |
Ongoing coverage of React2Shell