Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cc72-wc5x-7wmj

Опубликовано: 14 фев. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 3.1

Описание

Mattermost versions 9.11.x <= 9.11.6 fail to filter out DMs from the deleted channels endpoint which allows an attacker to infer user IDs and other metadata from deleted DMs if someone had manually marked DMs as deleted in the database.

Mattermost versions 9.11.x <= 9.11.6 fail to filter out DMs from the deleted channels endpoint which allows an attacker to infer user IDs and other metadata from deleted DMs if someone had manually marked DMs as deleted in the database.

EPSS

Процентиль: 29%
0.00107
Низкий

3.1 Low

CVSS3

Дефекты

CWE-754

Связанные уязвимости

CVSS3: 3.1
nvd
12 месяцев назад

Mattermost versions 9.11.x <= 9.11.6 fail to filter out DMs from the deleted channels endpoint which allows an attacker to infer user IDs and other metadata from deleted DMs if someone had manually marked DMs as deleted in the database.

CVSS3: 3.1
debian
12 месяцев назад

Mattermost versions 9.11.x <= 9.11.6 fail to filter out DMs from the d ...

EPSS

Процентиль: 29%
0.00107
Низкий

3.1 Low

CVSS3

Дефекты

CWE-754