Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4gj5-jpg2-r4vj

Опубликовано: 12 дек. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 3.7

Описание

Mattermost fails to validate team membership when a user attempts to access a playbook, allowing a user with permissions to a playbook but no permissions to the team the playbook is on to access and modify the playbook. This can happen if the user was once a member of the team, got permissions to the playbook and was then removed from the team. 

Mattermost fails to validate team membership when a user attempts to access a playbook, allowing a user with permissions to a playbook but no permissions to the team the playbook is on to access and modify the playbook. This can happen if the user was once a member of the team, got permissions to the playbook and was then removed from the team. 

EPSS

Процентиль: 48%
0.00247
Низкий

3.7 Low

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 3.7
nvd
около 2 лет назад

Mattermost fails to validate team membership when a user attempts to access a playbook, allowing a user with permissions to a playbook but no permissions to the team the playbook is on to access and modify the playbook. This can happen if the user was once a member of the team, got permissions to the playbook and was then removed from the team. 

CVSS3: 3.7
debian
около 2 лет назад

Mattermost fails to validate team membership when a user attempts to a ...

EPSS

Процентиль: 48%
0.00247
Низкий

3.7 Low

CVSS3

Дефекты

CWE-284