Описание
Mattermost fails to check the "Show Full Name" setting when rendering the result for the /plugins/focalboard/api/v2/users API call, allowing an attacker to learn the full name of a board owner.
Ссылки
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 7.5.0 (исключая)
cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*:*
EPSS
Процентиль: 39%
0.00168
Низкий
3.5 Low
CVSS3
4.3 Medium
CVSS3
Дефекты
CWE-200
CWE-668
Связанные уязвимости
CVSS3: 3.5
debian
около 2 лет назад
Mattermost fails to check the "Show Full Name" setting when rendering ...
CVSS3: 4.3
github
около 2 лет назад
Mattermost fails to check the "Show Full Name" setting when rendering the result for the /plugins/focalboard/api/v2/users API call, allowing an attacker to learn the full name of a board owner.
EPSS
Процентиль: 39%
0.00168
Низкий
3.5 Low
CVSS3
4.3 Medium
CVSS3
Дефекты
CWE-200
CWE-668