Описание
Mattermost password hash disclosure vulnerability
Mattermost fails to properly sanitize the user object when updating the username, resulting in the password hash being included in the response body.
Пакеты
github.com/mattermost/mattermost-server/v6
>= 5.4.0-rc1, < 7.8.12
7.8.12
github.com/mattermost/mattermost/server/v8
>= 8.0.0, < 8.0.4
8.0.4
github.com/mattermost/mattermost/server/v8
>= 8.1.0, < 8.1.3
8.1.3
github.com/mattermost/mattermost/server/v8
= 9.0.0
9.0.1
github.com/mattermost/mattermost/server/v8
< 8.0.0-20230825233148-f787fd63368a
8.0.0-20230825233148-f787fd63368a
github.com/mattermost/mattermost-server/v6
< 5.3.2-0.20230825233148-f787fd63368a
5.3.2-0.20230825233148-f787fd63368a
github.com/mattermost/mattermost-server/v5
< 5.3.2-0.20230825233148-f787fd63368a
5.3.2-0.20230825233148-f787fd63368a
github.com/mattermost/mattermost-server
< 5.3.2-0.20230825233148-f787fd63368a
5.3.2-0.20230825233148-f787fd63368a
Связанные уязвимости
Mattermost fails to properly sanitize the user object when updating the username, resulting in the password hash being included in the response body.
Mattermost fails to properly sanitize the user object when updating th ...