Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7qh6-7gxc-2q62

Опубликовано: 25 апр. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 3.1

Описание

When archiving a team, Mattermost fails to sanitize the related Websocket event sent to currently connected clients. This allows the clients to see the name, display name, description, and other data about the archived team.

When archiving a team, Mattermost fails to sanitize the related Websocket event sent to currently connected clients. This allows the clients to see the name, display name, description, and other data about the archived team.

EPSS

Процентиль: 60%
0.00398
Низкий

3.1 Low

CVSS3

Дефекты

CWE-200

Связанные уязвимости

redhat
почти 3 года назад

When archiving a team, Mattermost fails to sanitize the related Websocket event sent to currently connected clients. This allows the clients to see the name, display name, description, and other data about the archived team.

CVSS3: 3.1
nvd
почти 3 года назад

When archiving a team, Mattermost fails to sanitize the related Websocket event sent to currently connected clients. This allows the clients to see the name, display name, description, and other data about the archived team.

CVSS3: 3.1
debian
почти 3 года назад

When archiving a team, Mattermost fails to sanitize the related Websoc ...

EPSS

Процентиль: 60%
0.00398
Низкий

3.1 Low

CVSS3

Дефекты

CWE-200