Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-6517

Опубликовано: 15 июн. 2026
Источник: nvd
CVSS3: 6.3
CVSS3: 7.7
EPSS Низкий

Описание

Mattermost Desktop App versions <=6.1 5.5.13.0 fail to restrict the allow list of domains to which NTLM credentials were forwarded to in the Mattermost Desktop App which allows any user on a server without the image proxy enabled to intercept other users credentials via embedding an image that routes to an external web server. Mattermost Advisory ID: MMSA-2026-00651

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:mattermost:mattermost_desktop:*:-:*:*:*:*:*:*
Версия до 5.13.0 (включая)
cpe:2.3:a:mattermost:mattermost_desktop:*:*:*:*:*:*:*:*
Версия от 6.1.0 (включая) до 6.1.5 (включая)

EPSS

Процентиль: 8%
0.00187
Низкий

6.3 Medium

CVSS3

7.7 High

CVSS3

Дефекты

CWE-522

Связанные уязвимости

CVSS3: 6.3
github
около 2 месяцев назад

Mattermost Desktop App versions <=6.1 5.5.13.0 fail to restrict the allow list of domains to which NTLM credentials were forwarded to in the Mattermost Desktop App which allows any user on a server without the image proxy enabled to intercept other users credentials via embedding an image that routes to an external web server. Mattermost Advisory ID: MMSA-2026-00651

EPSS

Процентиль: 8%
0.00187
Низкий

6.3 Medium

CVSS3

7.7 High

CVSS3

Дефекты

CWE-522