-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from missing origin validation in integration action processing. The most logical location for this flaw would be in the post action handler that executes actions like post deletion. The function would normally be responsible for checking authorization context against post metadata, but the CWE-862 indicates this check was missing. The medium confidence reflects the lack of direct code/patch references, but matches the described vulnerability pattern in webhook/integration handling systems.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| github.com/mattermost/mattermost/server/v8 | go | < 8.0.0-20240926115259-20ed58906adc | 8.0.0-20240926115259-20ed58906adc |
Ongoing coverage of React2Shell