Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3q29-6c6h-84hh

Опубликовано: 15 июл. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

The Guest account feature in Mattermost version 6.7.0 and earlier fails to properly restrict the permissions, which allows a guest user to fetch a list of all public channels in the team, in spite of not being part of those channels.

The Guest account feature in Mattermost version 6.7.0 and earlier fails to properly restrict the permissions, which allows a guest user to fetch a list of all public channels in the team, in spite of not being part of those channels.

EPSS

Процентиль: 36%
0.00143
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-200
CWE-668
CWE-863

Связанные уязвимости

CVSS3: 4.3
nvd
почти 3 года назад

The Guest account feature in Mattermost version 6.7.0 and earlier fails to properly restrict the permissions, which allows a guest user to fetch a list of all public channels in the team, in spite of not being part of those channels.

CVSS3: 4.3
debian
почти 3 года назад

The Guest account feature in Mattermost version 6.7.0 and earlier fail ...

EPSS

Процентиль: 36%
0.00143
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-200
CWE-668
CWE-863