Mattermost是美国Mattermost公司的一个开源协作平台。 Mattermost Boards 插件 v0.10.0 及更早版本存在安全漏洞,该漏洞允许经过身份验证和未经授权的用户访问此信息,从而导致敏感和私人信息泄露。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Mattermost | Mattermost Boards | unspecified ~ 0.10.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-37866 | 4.7 MEDIUM | Session is not invalidated on server-side when user logged out of Boards |
| CVE-2021-37865 | 4.3 MEDIUM | Server-side Denial of Service while processing a specifically crafted GIF file |
| CVE-2021-37864 | 2.6 LOW | Users can view the contents of an archived channel when access is explicitly denied by the |
No comments yet