Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-898c-6fq9-5cv9

Опубликовано: 19 янв. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

Mattermost 6.1 and earlier fails to sufficiently validate permissions while viewing archived channels, which allows authenticated users to view contents of archived channels even when this is denied by system administrators by directly accessing the APIs.

Mattermost 6.1 and earlier fails to sufficiently validate permissions while viewing archived channels, which allows authenticated users to view contents of archived channels even when this is denied by system administrators by directly accessing the APIs.

EPSS

Процентиль: 45%
0.0022
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 2.6
nvd
больше 3 лет назад

Mattermost 6.1 and earlier fails to sufficiently validate permissions while viewing archived channels, which allows authenticated users to view contents of archived channels even when this is denied by system administrators by directly accessing the APIs.

CVSS3: 2.6
debian
больше 3 лет назад

Mattermost 6.1 and earlier fails to sufficiently validate permissions ...

EPSS

Процентиль: 45%
0.0022
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-863