Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-326r-7r4v-wq8c

Опубликовано: 26 сент. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 3.1

Описание

Mattermost versions 9.5.x <= 9.5.8 fail to properly authorize access to archived channels when viewing archived channels is disabled, which allows an attacker to view posts and files of archived channels via file links.

Mattermost versions 9.5.x <= 9.5.8 fail to properly authorize access to archived channels when viewing archived channels is disabled, which allows an attacker to view posts and files of archived channels via file links.

EPSS

Процентиль: 42%
0.00204
Низкий

3.1 Low

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 3.1
nvd
больше 1 года назад

Mattermost versions 9.5.x <= 9.5.8 fail to properly authorize access to archived channels when viewing archived channels is disabled, which allows an attacker to view posts and files of archived channels via file links.

CVSS3: 3.1
debian
больше 1 года назад

Mattermost versions 9.5.x <= 9.5.8 fail to properly authorize access t ...

EPSS

Процентиль: 42%
0.00204
Низкий

3.1 Low

CVSS3

Дефекты

CWE-284