Описание
Mattermost versions 9.5.x <= 9.5.9 fail to properly filter the channel data when ElasticSearch is enabled which allows a user to get private channel names by using cmd+K/ctrl+K.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| mattermost-server | itp | package |
EPSS
Процентиль: 50%
0.00267
Низкий
Связанные уязвимости
CVSS3: 4.3
nvd
больше 1 года назад
Mattermost versions 9.5.x <= 9.5.9 fail to properly filter the channel data when ElasticSearch is enabled which allows a user to get private channel names by using cmd+K/ctrl+K.
CVSS3: 4.3
github
больше 1 года назад
Mattermost Server allows user to get private channel names
EPSS
Процентиль: 50%
0.00267
Низкий