Описание
Mattermost fails to properly sanitize the user object when updating the username, resulting in the password hash being included in the response body.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| mattermost-server | itp | package |
EPSS
Процентиль: 34%
0.00139
Низкий
Связанные уязвимости
CVSS3: 4.9
nvd
около 2 лет назад
Mattermost fails to properly sanitize the user object when updating the username, resulting in the password hash being included in the response body.
CVSS3: 4.9
github
около 2 лет назад
Mattermost password hash disclosure vulnerability
EPSS
Процентиль: 34%
0.00139
Низкий