Описание
Mattermost 6.1 and earlier fails to sufficiently validate permissions while viewing archived channels, which allows authenticated users to view contents of archived channels even when this is denied by system administrators by directly accessing the APIs.
Ссылки
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 6.1 (включая)
cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*:*
EPSS
Процентиль: 45%
0.0022
Низкий
2.6 Low
CVSS3
6.5 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-284
CWE-863
Связанные уязвимости
CVSS3: 2.6
debian
больше 3 лет назад
Mattermost 6.1 and earlier fails to sufficiently validate permissions ...
CVSS3: 6.5
github
больше 3 лет назад
Mattermost 6.1 and earlier fails to sufficiently validate permissions while viewing archived channels, which allows authenticated users to view contents of archived channels even when this is denied by system administrators by directly accessing the APIs.
EPSS
Процентиль: 45%
0.0022
Низкий
2.6 Low
CVSS3
6.5 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-284
CWE-863