Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-1952

Опубликовано: 29 фев. 2024
Источник: debian
EPSS Низкий

Описание

Mattermost version 8.1.x before 8.1.9 fails to sanitize data associated with permalinks when a plugin updates an ephemeral post, allowing an authenticated attacker who can control the ephemeral post update to access individual posts' contents in channels they are not a member of.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mattermost-serveritppackage

EPSS

Процентиль: 49%
0.00263
Низкий

Связанные уязвимости

CVSS3: 3.1
nvd
почти 2 года назад

Mattermost version 8.1.x before 8.1.9 fails to sanitize data associated with permalinks when a plugin updates an ephemeral post, allowing an authenticated attacker who can control the ephemeral post update to access individual posts' contents in channels they are not a member of.

CVSS3: 3.1
github
почти 2 года назад

Mattermost incorrectly allows access individual posts

EPSS

Процентиль: 49%
0.00263
Низкий