Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Mattermost thread memberships persist after team removal, exposing private channel thread metadata on re-invite
Vulnerability Description
Mattermost versions 10.11.x <= 10.11.20, 11.7.x <= 11.7.5 Mattermost fails to remove thread membership records when a user is removed from or leaves a team, which allows a previously removed user who is later re-invited to the team to view private channel thread root post content and metadata via the team threads API.. Mattermost Advisory ID: MMSA-2026-00682
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
Vulnerability Type
清理环节不完整
Vulnerability Title
Mattermost 资源管理错误漏洞
Vulnerability Description
Mattermost是美国Mattermost公司开源的一个开源协作平台。 Mattermost 10.11.20及之前的10.11.x版本和11.7.5及之前的11.7.x版本存在资源管理错误漏洞,该漏洞源于当用户被移除或离开团队时未删除线程成员记录,可能导致重新邀请的用户通过团队线程API查看私有频道线程根帖内容和元数据。
CVSS Information
N/A
Vulnerability Type
N/A