Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jq35-5w25-hqv7

Опубликовано: 18 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 3.6

Описание

Mattermost Desktop App versions <=6.2 6.2.2.0 fail to redact the pre-auth secret when generating a diagnostics report, which allows a local attacker with access to a user's diagnostics report or log files to obtain the plaintext pre-auth secret configured for a connected server via inspecting the Server Connectivity (Step-3) diagnostics output. Mattermost Advisory ID: MMSA-2026-00716

Mattermost Desktop App versions <=6.2 6.2.2.0 fail to redact the pre-auth secret when generating a diagnostics report, which allows a local attacker with access to a user's diagnostics report or log files to obtain the plaintext pre-auth secret configured for a connected server via inspecting the Server Connectivity (Step-3) diagnostics output. Mattermost Advisory ID: MMSA-2026-00716

EPSS

Процентиль: 1%
0.00093
Низкий

3.6 Low

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 3.6
nvd
23 дня назад

Mattermost Desktop App versions <=6.2 6.2.2.0 fail to redact the pre-auth secret when generating a diagnostics report, which allows a local attacker with access to a user's diagnostics report or log files to obtain the plaintext pre-auth secret configured for a connected server via inspecting the Server Connectivity (Step-3) diagnostics output. Mattermost Advisory ID: MMSA-2026-00716

EPSS

Процентиль: 1%
0.00093
Низкий

3.6 Low

CVSS3

Дефекты

CWE-200