Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x444-p8vv-928w

Опубликовано: 27 фев. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 2.7

Описание

Mattermost fails to honor the ShowEmailAddress setting when constructing a response to the "Regenerate Invite Id" API endpoint, allowing an attacker with team admin privileges to learn the team owner's email address in the response.

Mattermost fails to honor the ShowEmailAddress setting when constructing a response to the "Regenerate Invite Id" API endpoint, allowing an attacker with team admin privileges to learn the team owner's email address in the response.

EPSS

Процентиль: 45%
0.00224
Низкий

2.7 Low

CVSS3

Дефекты

CWE-668

Связанные уязвимости

CVSS3: 2.7
nvd
почти 3 года назад

Mattermost fails to honor the ShowEmailAddress setting when constructing a response to the "Regenerate Invite Id" API endpoint, allowing an attacker with team admin privileges to learn the team owner's email address in the response.

CVSS3: 2.7
debian
почти 3 года назад

Mattermost fails to honor the ShowEmailAddress setting when constructi ...

EPSS

Процентиль: 45%
0.00224
Низкий

2.7 Low

CVSS3

Дефекты

CWE-668