Описание
Mattermost versions 9.5.x <= 9.5.8 fail to include the metadata endpoints of Oracle Cloud and Alibaba in the SSRF denylist, which allows an attacker to possibly cause an SSRF if Mattermost was deployed in Oracle Cloud or Alibaba.
Ссылки
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 9.5.0 (включая) до 9.5.9 (исключая)
cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
EPSS
Процентиль: 43%
0.00204
Низкий
3.1 Low
CVSS3
5.4 Medium
CVSS3
Дефекты
CWE-918
CWE-918
Связанные уязвимости
CVSS3: 3.1
debian
больше 1 года назад
Mattermost versions 9.5.x <= 9.5.8 fail to include themetadata endpoin ...
CVSS3: 3.1
github
больше 1 года назад
Mattermost versions 9.5.x <= 9.5.8 fail to include the metadata endpoints of Oracle Cloud and Alibaba in the SSRF denylist, which allows an attacker to possibly cause an SSRF if Mattermost was deployed in Oracle Cloud or Alibaba.
EPSS
Процентиль: 43%
0.00204
Низкий
3.1 Low
CVSS3
5.4 Medium
CVSS3
Дефекты
CWE-918
CWE-918