Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4x9v-95w9-xp83

Опубликовано: 16 июн. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.2

Описание

Mattermost fails to check if an admin user account active after an oauth2 flow is started, allowing an attacker with admin privileges to retain persistent access to Mattermost by obtaining an oauth2 access token while the attacker's account is deactivated.

Mattermost fails to check if an admin user account active after an oauth2 flow is started, allowing an attacker with admin privileges to retain persistent access to Mattermost by obtaining an oauth2 access token while the attacker's account is deactivated.

EPSS

Процентиль: 21%
0.00067
Низкий

6.2 Medium

CVSS3

Дефекты

CWE-613
CWE-862

Связанные уязвимости

CVSS3: 6.2
nvd
около 2 лет назад

Mattermost fails to check if an admin user account active after an oauth2 flow is started, allowing an attacker with admin privileges to retain persistent access to Mattermost by obtaining an oauth2 access token while the attacker's account is deactivated.

CVSS3: 6.2
debian
около 2 лет назад

Mattermost fails to check if an admin user account active after an oau ...

EPSS

Процентиль: 21%
0.00067
Низкий

6.2 Medium

CVSS3

Дефекты

CWE-613
CWE-862