Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w3q2-jmrg-5rfm

Опубликовано: 22 мар. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

Mattermost fails to check the "Show Full Name" setting when rendering the result for the /plugins/focalboard/api/v2/users API call, allowing an attacker to learn the full name of a board owner.

Mattermost fails to check the "Show Full Name" setting when rendering the result for the /plugins/focalboard/api/v2/users API call, allowing an attacker to learn the full name of a board owner.

EPSS

Процентиль: 39%
0.00168
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-668

Связанные уязвимости

CVSS3: 3.5
nvd
около 2 лет назад

Mattermost fails to check the "Show Full Name" setting when rendering the result for the /plugins/focalboard/api/v2/users API call, allowing an attacker to learn the full name of a board owner.

CVSS3: 3.5
debian
около 2 лет назад

Mattermost fails to check the "Show Full Name" setting when rendering ...

EPSS

Процентиль: 39%
0.00168
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-668