Metrics
Affected Vendors & Products
No advisories yet.
Solution
Update Mattermost to versions 11.1.0, 10.11.6, 11.0.5, 10.12.3 or higher.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
Wed, 17 Dec 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 17 Dec 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mattermost versions 10.11.x <= 10.11.5, 11.0.x <= 11.0.4, 10.12.x <= 10.12.2 fail to invalidate invite tokens after use which allows malicious actors who have intercepted invite tokens to manipulate channel memberships including adding or removing users from private channels via token replay attack. | |
| Title | Mattermost Remote Cluster Invite Token Replay | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2025-12-17T19:29:39.872Z
Reserved: 2025-11-17T17:07:12.922Z
Link: CVE-2025-13324
Updated: 2025-12-17T18:52:27.669Z
Status : Received
Published: 2025-12-17T19:16:01.093
Modified: 2025-12-17T19:16:01.093
Link: CVE-2025-13324
No data.
OpenCVE Enrichment
No data.