Описание
Mattermost Server allows attackers to log sensitive information via DEBUG REST API logging endpoint
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows attackers to add DEBUG lines to the logs via a REST API version 3 logging endpoint.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2017-18896
- https://github.com/mattermost/mattermost/commit/3c34e2b2dcb0fde96a10e68d877aa7d0ab511669
- https://github.com/mattermost/mattermost/commit/722fb1947a2e7395ccf16adce9206736d803a9f3
- https://github.com/mattermost/mattermost/commit/d38328976e2c8bb0fab91e656042a0d8ac37bc76
- https://github.com/mattermost/mattermost
- https://mattermost.com/security-updates
Пакеты
Наименование
github.com/mattermost/mattermost-server
go
Затронутые версииВерсия исправления
>= 4.1.0, < 4.1.1
4.1.1
Наименование
github.com/mattermost/mattermost-server
go
Затронутые версииВерсия исправления
< 4.0.5
4.0.5
Наименование
github.com/mattermost/mattermost-server
go
Затронутые версииВерсия исправления
>= 4.2.0-rc1, < 4.2.0
4.2.0
Связанные уязвимости
CVSS3: 5.3
nvd
больше 5 лет назад
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows attackers to add DEBUG lines to the logs via a REST API version 3 logging endpoint.
CVSS3: 5.3
debian
больше 5 лет назад
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and ...