CVE-2025-13324
Estado: AnalizadaBaja (3.7)—
Mattermost versions 10.11.x <= 10.11.5, 11.0.x <= 11.0.4, 10.12.x <= 10.12.2 fail to invalidate remote cluster invite tokens when using the legacy (version 1) protocol or when the confirming party does not provide a refreshed token, which allows an attacker who has obtained an invite token to authenticate as the remote cluster and perform limited actions on shared channels even after the invitation has been legitimately confirmed.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
- Puntuación base: 3.7
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.20%
- Percentil entre todas las CVEs puntuadas: 9
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-863
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-13324",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-13324",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-12-17T18:52:25.155977Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "responsibledisclosure@mattermost.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 3.7,
"attackVector": "NETWORK",
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 2.2
}
]
},
"affected": [
{
"source": "responsibledisclosure@mattermost.com",
"affectedData": [
{
"vendor": "Mattermost",
"product": "Mattermost",
"versions": [
{
"status": "affected",
"version": "10.11.0",
"versionType": "semver",
"lessThanOrEqual": "10.11.5"
},
{
"status": "affected",
"version": "11.0.0",
"versionType": "semver",
"lessThanOrEqual": "11.0.4"
},
{
"status": "affected",
"version": "10.12.0",
"versionType": "semver",
"lessThanOrEqual": "10.12.2"
},
{
"status": "unaffected",
"version": "11.1.0"
},
{
"status": "unaffected",
"version": "10.11.6"
},
{
"status": "unaffected",
"version": "11.0.5"
},
{
"status": "unaffected",
"version": "10.12.3"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2025-12-17T19:16:01.093",
"references": [
{
"url": "https://mattermost.com/security-updates",
"tags": [
"Vendor Advisory"
],
"source": "responsibledisclosure@mattermost.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "responsibledisclosure@mattermost.com",
"description": [
{
"lang": "en",
"value": "CWE-863"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Mattermost versions 10.11.x <= 10.11.5, 11.0.x <= 11.0.4, 10.12.x <= 10.12.2 fail to invalidate remote cluster invite tokens when using the legacy (version 1) protocol or when the confirming party does not provide a refreshed token, which allows an attacker who has obtained an invite token to authenticate as the remote cluster and perform limited actions on shared channels even after the invitation has been legitimately confirmed."
}
],
"lastModified": "2026-06-17T08:33:56.323",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "01DCCC9D-79BE-4B4D-9ECC-1299F88541D8",
"versionEndExcluding": "10.11.6",
"versionStartIncluding": "10.11.0"
},
{
"criteria": "cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DD0ED714-56F9-4C84-B84D-3BF658940568",
"versionEndExcluding": "10.12.3",
"versionStartIncluding": "10.12.0"
},
{
"criteria": "cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6130B691-5017-418D-A28A-84A83AA2496C",
"versionEndExcluding": "11.0.5",
"versionStartIncluding": "11.0.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "responsibledisclosure@mattermost.com"
}