Описание
Mattermost 6.1 and earlier fails to sufficiently validate permissions while viewing archived channels, which allows authenticated users to view contents of archived channels even when this is denied by system administrators by directly accessing the APIs.
Ссылки
- Vendor Advisory
 - Vendor Advisory
 
Уязвимые конфигурации
Конфигурация 1Версия до 6.1 (включая)
cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*:*
EPSS
Процентиль: 40%
0.00177
Низкий
2.6 Low
CVSS3
6.5 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-284
CWE-863
Связанные уязвимости
CVSS3: 2.6
debian
почти 4 года назад
Mattermost 6.1 and earlier fails to sufficiently validate permissions ...
CVSS3: 6.5
github
почти 4 года назад
Mattermost 6.1 and earlier fails to sufficiently validate permissions while viewing archived channels, which allows authenticated users to view contents of archived channels even when this is denied by system administrators by directly accessing the APIs.
EPSS
Процентиль: 40%
0.00177
Низкий
2.6 Low
CVSS3
6.5 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-284
CWE-863