Описание
Mattermost leaks details of AD/LDAP groups of a teams
Mattermost fails to properly authorize the requests fetching team associated AD/LDAP groups, allowing a user to fetch details of AD/LDAP groups of a team that they are not a member of.
Пакеты
github.com/mattermost/mattermost/server/v8
>= 9.4.0, < 9.4.2
9.4.2
github.com/mattermost/mattermost/server/v8
>= 9.3.0, < 9.3.1
9.3.1
github.com/mattermost/mattermost/server/v8
>= 9.2.0, < 9.2.5
9.2.5
EPSS
5.3 Medium
CVSS4
4.3 Medium
CVSS3
CVE ID
Дефекты
Связанные уязвимости
Mattermost fails to properly authorize the requests fetching team associated AD/LDAP groups, allowing a user to fetch details of AD/LDAP groups of a team that they are not a member of.
Mattermost fails to properly authorize the requests fetchingteam assoc ...
Уязвимость компонента /plugins/playbooks/api/v0/telemetry/run/ приложения для обмена мгновенными сообщениями Mattermost, позволяющая нарушителю получить несанкционированный доступ к информации о пользователях AD/LDAP
EPSS
5.3 Medium
CVSS4
4.3 Medium
CVSS3