Описание
Mattermost Boards plugin v0.10.0 and earlier fails to invalidate a session on the server-side when a user logged out of Boards, which allows an attacker to reuse old session token for authorization.
Ссылки
- Vendor Advisory
- ExploitThird Party Advisory
- Vendor Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.10.0 (включая)
cpe:2.3:a:mattermost:mattermost_boards:*:*:*:*:*:*:*:*
EPSS
Процентиль: 41%
0.0019
Низкий
4.7 Medium
CVSS3
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-613
CWE-613
Связанные уязвимости
github
около 4 лет назад
Mattermost Boards plugin v0.10.0 and earlier fails to invalidate a session on the server-side when a user logged out of Boards, which allows an attacker to reuse old session token for authorization.
EPSS
Процентиль: 41%
0.0019
Низкий
4.7 Medium
CVSS3
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-613
CWE-613