8.2
CVE-2024-11599
- EPSS 0.07%
- Veröffentlicht 28.11.2024 10:15:06
- Zuletzt bearbeitet 01.10.2025 18:25:03
- Quelle responsibledisclosure@mattermo
- CVE-Watchlists
- Unerledigt
Domain Restriction Bypass on Registration
Mattermost versions 10.0.x <= 10.0.1, 10.1.x <= 10.1.1, 9.11.x <= 9.11.3, 9.5.x <= 9.5.11 fail to properly validate email addresses which allows an unauthenticated user to bypass email domain restrictions via carefully crafted input on email registration.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mattermost ≫ Mattermost Server Version >= 9.5.0 < 9.5.12
Mattermost ≫ Mattermost Server Version >= 9.11.0 < 9.11.4
Mattermost ≫ Mattermost Server Version >= 10.0.0 < 10.0.2
Mattermost ≫ Mattermost Server Version >= 10.1.0 < 10.1.2
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.07% | 0.215 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
|
| responsibledisclosure@mattermost.com | 8.2 | 3.9 | 4.2 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
|
CWE-754 Improper Check for Unusual or Exceptional Conditions
The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product.