Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2wmq-3m94-g4jr

Опубликовано: 15 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 6.3

Описание

Mattermost Desktop App versions <=6.1 5.5.13.0 fail to restrict the allow list of domains to which NTLM credentials were forwarded to in the Mattermost Desktop App which allows any user on a server without the image proxy enabled to intercept other users credentials via embedding an image that routes to an external web server. Mattermost Advisory ID: MMSA-2026-00651

Mattermost Desktop App versions <=6.1 5.5.13.0 fail to restrict the allow list of domains to which NTLM credentials were forwarded to in the Mattermost Desktop App which allows any user on a server without the image proxy enabled to intercept other users credentials via embedding an image that routes to an external web server. Mattermost Advisory ID: MMSA-2026-00651

EPSS

Процентиль: 9%
0.00187
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-522

Связанные уязвимости

CVSS3: 6.3
nvd
около 2 месяцев назад

Mattermost Desktop App versions <=6.1 5.5.13.0 fail to restrict the allow list of domains to which NTLM credentials were forwarded to in the Mattermost Desktop App which allows any user on a server without the image proxy enabled to intercept other users credentials via embedding an image that routes to an external web server. Mattermost Advisory ID: MMSA-2026-00651

EPSS

Процентиль: 9%
0.00187
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-522