Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x5q7-p9g5-58x7

Опубликовано: 15 июл. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 4.2

Описание

Mattermost Mobile Apps versions <=2.16.0 fail to validate that the push notifications received for a server actually came from this serve that which allows a malicious server to send push notifications with another server’s diagnostic ID or server URL and have them show up in mobile apps as that server’s push notifications.

Mattermost Mobile Apps versions <=2.16.0 fail to validate that the push notifications received for a server actually came from this serve that which allows a malicious server to send push notifications with another server’s diagnostic ID or server URL and have them show up in mobile apps as that server’s push notifications.

EPSS

Процентиль: 33%
0.00129
Низкий

4.2 Medium

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 4.2
nvd
больше 1 года назад

Mattermost Mobile Apps versions <=2.16.0 fail to validate that the push notifications received for a server actually came from this serve that which allows a malicious server to send push notifications with another server’s diagnostic ID or server URL and have them show up in mobile apps as that server’s push notifications.

EPSS

Процентиль: 33%
0.00129
Низкий

4.2 Medium

CVSS3

Дефекты

CWE-287