Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rr84-59x2-rrf4

Опубликовано: 14 апр. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

Mattermost Playbooks plugin v1.24.0 and earlier fails to properly check the limit on the number of webhooks, which allows authenticated and authorized users to create a specifically drafted Playbook which could trigger a large amount of webhook requests leading to Denial of Service.

Mattermost Playbooks plugin v1.24.0 and earlier fails to properly check the limit on the number of webhooks, which allows authenticated and authorized users to create a specifically drafted Playbook which could trigger a large amount of webhook requests leading to Denial of Service.

EPSS

Процентиль: 58%
0.00363
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 3.5
nvd
почти 4 года назад

Mattermost Playbooks plugin v1.24.0 and earlier fails to properly check the limit on the number of webhooks, which allows authenticated and authorized users to create a specifically drafted Playbook which could trigger a large amount of webhook requests leading to Denial of Service.

EPSS

Процентиль: 58%
0.00363
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-770