Опубликовано: 02 янв. 2024
Источник: github
Github: Прошло ревью
CVSS4: 5.3
CVSS3: 4.3
Описание
Mattermost notified all users in the channel when using WebSockets to respond individually
Mattermost fails to scope the WebSocket response around notified users to a each user separately resulting in the WebSocket broadcasting the information about who was notified about a post to everyone else in the channel.
Пакеты
Наименование
github.com/mattermost/mattermost/server/v8
go
Затронутые версииВерсия исправления
<= 8.1.6
8.1.7
Наименование
github.com/mattermost/mattermost-server/v6
go
Затронутые версииВерсия исправления
<= 8.1.6
8.1.7
Связанные уязвимости
CVSS3: 4.3
nvd
около 2 лет назад
Mattermost fails to scope the WebSocket response around notified users to a each user separately resulting in the WebSocket broadcasting the information about who was notified about a post to everyone else in the channel.
CVSS3: 4.3
debian
около 2 лет назад
Mattermost fails to scope the WebSocket response around notified users ...