Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in Mattermost Server before 4.5.0, 4.4.5, and 4.3.4. It mishandled webhook access control in the EnableOnlyAdminIntegrations case.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Mattermost Server 安全漏洞
Vulnerability Description
Mattermost Server是美国Mattermost公司的一套开源的消息传递平台。 Mattermost Server 4.5.0之前版本、4.4.5之前版本和4.3.4之前版本中存在安全漏洞,该漏洞源于在‘EnableOnlyAdminIntegration’被设置成false时,程序没有正确处理webhook的访问控制。攻击者可利用该漏洞伪造请求,编辑其他用户的webhooks。
CVSS Information
N/A
Vulnerability Type
N/A