Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gr4w-63r3-8h38

Опубликовано: 26 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 6.8

Описание

Mattermost Plugins versions <=11.6 10.18.11 11.3.6 11.6.5.0 fail to sanitize error responses from the OpenAI API before logging, which allows a user with access to server logs or support packets to obtain a valid or partially reconstructable OpenAI API key via inspection of mattermost.log entries generated during authentication failures. Mattermost Advisory ID: MMSA-2026-00609

Mattermost Plugins versions <=11.6 10.18.11 11.3.6 11.6.5.0 fail to sanitize error responses from the OpenAI API before logging, which allows a user with access to server logs or support packets to obtain a valid or partially reconstructable OpenAI API key via inspection of mattermost.log entries generated during authentication failures. Mattermost Advisory ID: MMSA-2026-00609

EPSS

Процентиль: 24%
0.00325
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-532

Связанные уязвимости

CVSS3: 6.8
nvd
около 1 месяца назад

Mattermost Plugins versions <=11.6 10.18.11 11.3.6 11.6.5.0 fail to sanitize error responses from the OpenAI API before logging, which allows a user with access to server logs or support packets to obtain a valid or partially reconstructable OpenAI API key via inspection of mattermost.log entries generated during authentication failures. Mattermost Advisory ID: MMSA-2026-00609

EPSS

Процентиль: 24%
0.00325
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-532