Описание
Mattermost race condition
A race condition in Mattermost versions 8.1.x before 8.1.9, and 9.4.x before 9.4.2 allows an authenticated attacker to gain unauthorized access to individual posts' contents via carefully timed post creation while another user deletes posts.
Пакеты
Наименование
github.com/mattermost/mattermost/server/v8
go
Затронутые версииВерсия исправления
>= 9.0.0, < 9.4.2
9.4.2
Наименование
github.com/mattermost/mattermost/server/v8
go
Затронутые версииВерсия исправления
< 8.1.9
8.1.9
Связанные уязвимости
CVSS3: 2.6
nvd
почти 2 года назад
A race condition in Mattermost versions 8.1.x before 8.1.9, and 9.4.x before 9.4.2 allows an authenticated attacker to gain unauthorized access to individual posts' contents via carefully timed post creation while another user deletes posts.
CVSS3: 2.6
debian
почти 2 года назад
A race condition in Mattermost versions 8.1.x before 8.1.9, and 9.4.x ...