Описание
Mattermost fails to properly sanitize the user object when updating the username, resulting in the password hash being included in the response body.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| mattermost-server | itp | package |
Связанные уязвимости
CVSS3: 4.9
nvd
около 2 лет назад
Mattermost fails to properly sanitize the user object when updating the username, resulting in the password hash being included in the response body.
CVSS3: 4.9
github
около 2 лет назад
Mattermost password hash disclosure vulnerability