Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jj46-9cgh-qmfx

Опубликовано: 27 нояб. 2023
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Mattermost Improper Access Control vulnerability

Mattermost fails to check if hardened mode is enabled when overriding the username and/or the icon when posting a post. If settings allowed integrations to override the username and profile picture when posting, a member could also override the username and icon when making a post even if the Hardened Mode setting was enabled

Пакеты

Наименование

github.com/mattermost/mattermost/server/v8

go
Затронутые версииВерсия исправления

< 8.1.4

8.1.4

Наименование

github.com/mattermost/mattermost-server/v6

go
Затронутые версииВерсия исправления

< 7.8.13

7.8.13

EPSS

Процентиль: 30%
0.00107
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 4.3
nvd
больше 1 года назад

Mattermost fails to check if hardened mode is enabled when overriding the username and/or the icon when posting a post. If settings allowed integrations to override the username and profile picture when posting, a member could also override the username and icon when making a post even if the Hardened Mode setting was enabled

CVSS3: 4.3
debian
больше 1 года назад

Mattermost fails to check if hardened mode is enabled when overriding ...

EPSS

Процентиль: 30%
0.00107
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-284