Логотип exploitDog
bind:CVE-2024-36257
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-36257

Количество 3

Количество 3

nvd логотип

CVE-2024-36257

12 месяцев назад

Mattermost versions 9.5.x <= 9.5.5 and 9.8.0, when using shared channels with multiple remote servers connected, fail to check that the remote server A requesting the server B to update the profile picture of a user is the remote that actually has the user as a local one . This allows a malicious remote A to change the profile images of users that belong to another remote server C that is connected to the server A.

CVSS3: 2.7
EPSS: Низкий
debian логотип

CVE-2024-36257

12 месяцев назад

Mattermost versions 9.5.x <= 9.5.5 and 9.8.0,when using shared channel ...

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-5cg2-wmx6-ccqv

12 месяцев назад

Mattermost versions 9.5.x <= 9.5.5 and 9.8.0, when using shared channels with multiple remote servers connected, fail to check that the remote server A requesting the server B to update the profile picture of a user is the remote that actually has the user as a local one . This allows a malicious remote A to change the profile images of users that belong to another remote server C that is connected to the server A.

CVSS3: 2.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-36257

Mattermost versions 9.5.x <= 9.5.5 and 9.8.0, when using shared channels with multiple remote servers connected, fail to check that the remote server A requesting the server B to update the profile picture of a user is the remote that actually has the user as a local one . This allows a malicious remote A to change the profile images of users that belong to another remote server C that is connected to the server A.

CVSS3: 2.7
0%
Низкий
12 месяцев назад
debian логотип
CVE-2024-36257

Mattermost versions 9.5.x <= 9.5.5 and 9.8.0,when using shared channel ...

CVSS3: 2.7
0%
Низкий
12 месяцев назад
github логотип
GHSA-5cg2-wmx6-ccqv

Mattermost versions 9.5.x <= 9.5.5 and 9.8.0, when using shared channels with multiple remote servers connected, fail to check that the remote server A requesting the server B to update the profile picture of a user is the remote that actually has the user as a local one . This allows a malicious remote A to change the profile images of users that belong to another remote server C that is connected to the server A.

CVSS3: 2.7
0%
Низкий
12 месяцев назад

Уязвимостей на страницу