Логотип exploitDog
bind:CVE-2025-27936
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-27936

Количество 2

Количество 2

nvd логотип

CVE-2025-27936

10 месяцев назад

Mattermost Plugin MSTeams versions <2.1.0 and Mattermost Server versions 10.5.x <=10.5.1 with the MS Teams plugin enabled fail to perform constant time comparison on a MSTeams plugin webhook secret which allows an attacker to retrieve the webhook secret of the MSTeams plugin via a timing attack during webhook secret comparison.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2j87-p623-8cc2

10 месяцев назад

Mattermost vulnerable to Observable Timing Discrepancy

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-27936

Mattermost Plugin MSTeams versions <2.1.0 and Mattermost Server versions 10.5.x <=10.5.1 with the MS Teams plugin enabled fail to perform constant time comparison on a MSTeams plugin webhook secret which allows an attacker to retrieve the webhook secret of the MSTeams plugin via a timing attack during webhook secret comparison.

CVSS3: 5.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-2j87-p623-8cc2

Mattermost vulnerable to Observable Timing Discrepancy

CVSS3: 5.3
0%
Низкий
10 месяцев назад

Уязвимостей на страницу