Dismissed
Permalink
CVE-2026-0997
4.3 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): LOW
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): NONE
- Integrity impact (I): LOW
- Availability impact (A): NONE
by @LeSuisse Activity log
- Created automatic suggestion
-
@LeSuisse
removed
6 packages
- mattermost-desktop
- python312Packages.mattermostdriver
- python313Packages.mattermostdriver
- python314Packages.mattermostdriver
- mattermost
- mattermostLatest
- @LeSuisse dismissed
Mattermost Zoom Plugin channel preference API lacks authorization checks
Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 and Mattermost Plugin Zoom versions <=1.11.0 fail to validate the authenticated user when processing {{/plugins/zoom/api/v1/channel-preference}}, which allows any logged-in user to change Zoom meeting restrictions for arbitrary channels via crafted API requests.. Mattermost Advisory ID: MMSA-2025-00558
References
- MMSA-2025-00558 vendor-advisory
- MMSA-2025-00558 vendor-advisory
Affected products
Mattermost
- =<10.11.9
- ==11.3.0
- ==11.1.3
- =<11.1.2
- ==11.2.2
- =<11.2.1
- ==10.11.10