Описание
Mattermost fails to properly sanitize the user object when updating the username, resulting in the password hash being included in the response body.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| mattermost-server | itp | package |
Связанные уязвимости
CVSS3: 4.9
nvd
почти 2 года назад
Mattermost fails to properly sanitize the user object when updating the username, resulting in the password hash being included in the response body.
CVSS3: 4.9
github
почти 2 года назад
Mattermost password hash disclosure vulnerability