Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pjqg-q843-gm7c

Опубликовано: 12 дек. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

Mattermost fails to perform authorization checks in the /plugins/playbooks/api/v0/runs/add-to-timeline-dialog endpoint of the Playbooks plugin allowing an attacker to get limited information about a post if they know the post ID

Mattermost fails to perform authorization checks in the /plugins/playbooks/api/v0/runs/add-to-timeline-dialog endpoint of the Playbooks plugin allowing an attacker to get limited information about a post if they know the post ID

EPSS

Процентиль: 41%
0.00192
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-200
CWE-639

Связанные уязвимости

CVSS3: 6.5
nvd
около 2 лет назад

Mattermost fails to perform authorization checks in the /plugins/playbooks/api/v0/runs/add-to-timeline-dialog endpoint of the Playbooks plugin allowing an attacker to get limited information about a post if they know the post ID

CVSS3: 6.5
debian
около 2 лет назад

Mattermost fails to perform authorization checks in the /plugins/play ...

EPSS

Процентиль: 41%
0.00192
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-200
CWE-639