Mattermost versions 10.11.x <= 10.11.5, 11.0.x <= 11.0.4, 10.12.x <= 10.12.2 fail to invalidate remote cluster invite tokens when using the legacy (version 1) protocol or when the confirming party does not provide a refreshed token, which allows an attacker who has obtained an invite token to authenticate as the remote cluster and perform limited actions on shared channels even after the invitation has been legitimately confirmed.
References
| Link | Resource |
|---|---|
| https://mattermost.com/security-updates | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2025-12-17 19:16
Updated : 2025-12-29 18:46
NVD link : CVE-2025-13324
Mitre link : CVE-2025-13324
CVE.ORG link : CVE-2025-13324
JSON object : View
Products Affected
mattermost
- mattermost_server
CWE
CWE-863
Incorrect Authorization
