Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-32046

Опубликовано: 26 апр. 2024
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

Mattermost versions 9.6.x <= 9.6.0, 9.5.x <= 9.5.2, 9.4.x <= 9.4.4 and 8.1.x <= 8.1.11 fail to remove detailed error messages in API requests even if the developer mode is off which allows an attacker to get information about the server such as the full path were files are stored

A flaw was found in Mattermost, where it fails to remove detailed error messages in API requests even if the developer mode is off. This flaw allows an attacker to obtain information about the server, such as the full path where files are stored.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/acm-grafana-rhel8Fix deferred
Red Hat Advanced Cluster Security 3advanced-cluster-security/rhacs-docs-rhel8Fix deferred
Red Hat Advanced Cluster Security 3advanced-cluster-security/rhacs-main-rhel8Fix deferred
Red Hat Advanced Cluster Security 3advanced-cluster-security/rhacs-rhel8-operatorFix deferred
Red Hat Advanced Cluster Security 3advanced-cluster-security/rhacs-roxctl-rhel8Fix deferred
Red Hat Advanced Cluster Security 3advanced-cluster-security/rhacs-scanner-db-rhel8Fix deferred
Red Hat Advanced Cluster Security 3advanced-cluster-security/rhacs-scanner-rhel8Fix deferred
Red Hat OpenShift Container Platform 4openshift4/ose-grafanaNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=2277327mattermost: allows an attacker to get information about the server such as the full path were files are stored

EPSS

Процентиль: 38%
0.00452
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
nvd
больше 2 лет назад

Mattermost versions 9.6.x <= 9.6.0, 9.5.x <= 9.5.2, 9.4.x <= 9.4.4 and 8.1.x <= 8.1.11 fail to remove detailed error messages in API requests even if the developer mode is off which allows an attacker to get information about the server such as the full path were files are stored

CVSS3: 4.3
debian
больше 2 лет назад

Mattermost versions 9.6.x <= 9.6.0, 9.5.x <= 9.5.2, 9.4.x <= 9.4.4 and ...

CVSS3: 4.3
github
больше 2 лет назад

Mattermost's detailed error messages reveal the full file path

EPSS

Процентиль: 38%
0.00452
Низкий

4.3 Medium

CVSS3

Уязвимость CVE-2024-32046