Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-898c-6fq9-5cv9

Опубликовано: 19 янв. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

Mattermost 6.1 and earlier fails to sufficiently validate permissions while viewing archived channels, which allows authenticated users to view contents of archived channels even when this is denied by system administrators by directly accessing the APIs.

Mattermost 6.1 and earlier fails to sufficiently validate permissions while viewing archived channels, which allows authenticated users to view contents of archived channels even when this is denied by system administrators by directly accessing the APIs.

EPSS

Процентиль: 40%
0.00177
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 2.6
nvd
почти 4 года назад

Mattermost 6.1 and earlier fails to sufficiently validate permissions while viewing archived channels, which allows authenticated users to view contents of archived channels even when this is denied by system administrators by directly accessing the APIs.

CVSS3: 2.6
debian
почти 4 года назад

Mattermost 6.1 and earlier fails to sufficiently validate permissions ...

EPSS

Процентиль: 40%
0.00177
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-863