Skip to content

Commit 276f2d7

Browse files
1 parent 1e72727 commit 276f2d7

File tree

2 files changed

+7
-3
lines changed

2 files changed

+7
-3
lines changed

advisories/github-reviewed/2024/01/GHSA-wjc4-73q6-gv3m/GHSA-wjc4-73q6-gv3m.json

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-wjc4-73q6-gv3m",
4-
"modified": "2024-01-03T19:38:54Z",
4+
"modified": "2025-12-26T15:16:48Z",
55
"published": "2024-01-03T06:30:27Z",
66
"aliases": [
77
"CVE-2023-46308"
@@ -59,6 +59,10 @@
5959
"type": "ADVISORY",
6060
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46308"
6161
},
62+
{
63+
"type": "WEB",
64+
"url": "https://github.com/plotly/plotly.R/issues/2463"
65+
},
6266
{
6367
"type": "WEB",
6468
"url": "https://github.com/plotly/plotly.js/commit/02498404c8ad7a3395191e65694fb142a37b0fe9"

advisories/github-reviewed/2025/12/GHSA-x3r8-2hmh-89f5/GHSA-x3r8-2hmh-89f5.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,13 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-x3r8-2hmh-89f5",
4-
"modified": "2025-12-20T17:27:10Z",
4+
"modified": "2025-12-26T15:17:57Z",
55
"published": "2025-12-17T21:30:48Z",
66
"aliases": [
77
"CVE-2025-13324"
88
],
99
"summary": "Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation",
10-
"details": "Mattermost versions 10.11.x < 10.11.5, 11.0.x < 11.0.4, 10.12.x < 10.12.2 fail to invalidate invite tokens after use which allows malicious actors who have intercepted invite tokens to manipulate channel memberships including adding or removing users from private channels via token replay attack.",
10+
"details": "Mattermost versions 10.11.x < 10.11.5, 11.0.x < 11.0.4, 10.12.x < 10.12.2 fail to invalidate remote cluster invite tokens when using the legacy (version 1) protocol or when the confirming party does not provide a refreshed token, which allows an attacker who has obtained an invite token to authenticate as the remote cluster and perform limited actions on shared channels even after the invitation has been legitimately confirmed.",
1111
"severity": [
1212
{
1313
"type": "CVSS_V3",

0 commit comments

Comments
 (0)