Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rgjp-xw8g-3xwx

Опубликовано: 19 мар. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.9

Описание

One of the API in Mattermost version 6.3.0 and earlier fails to properly protect the permissions, which allows the system administrators to combine the two distinct privileges/capabilities in a way that allows them to override certain restricted configurations like EnableUploads.

One of the API in Mattermost version 6.3.0 and earlier fails to properly protect the permissions, which allows the system administrators to combine the two distinct privileges/capabilities in a way that allows them to override certain restricted configurations like EnableUploads.

EPSS

Процентиль: 34%
0.00131
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 3.3
nvd
больше 3 лет назад

One of the API in Mattermost version 6.3.0 and earlier fails to properly protect the permissions, which allows the system administrators to combine the two distinct privileges/capabilities in a way that allows them to override certain restricted configurations like EnableUploads.

CVSS3: 3.3
debian
больше 3 лет назад

One of the API in Mattermost version 6.3.0 and earlier fails to proper ...

EPSS

Процентиль: 34%
0.00131
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-269