Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m2ch-x2q7-2284

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 8.8

Описание

Mattermost Server allows an attacker to specify a full pathname of a log file

An issue was discovered in Mattermost Server before 3.7.5. It allows an attacker to specify a full pathname of a log file.

Пакеты

Наименование

github.com/mattermost/mattermost-server

go
Затронутые версииВерсия исправления

< 3.7.4-0.20170404171331-0b5c0794fdcb

3.7.4-0.20170404171331-0b5c0794fdcb

EPSS

Процентиль: 70%
0.01375
Низкий

8.8 High

CVSS4

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 9.8
nvd
около 6 лет назад

An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. It allows an attacker to specify a full pathname of a log file.

CVSS3: 9.8
debian
около 6 лет назад

An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and ...

EPSS

Процентиль: 70%
0.01375
Низкий

8.8 High

CVSS4

Дефекты

CWE-22