Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Restricted custom admin role can bypass the restrictions and view the server logs and server config.json file contents
Vulnerability Description
One of the API in Mattermost version 6.4.1 and earlier fails to properly protect the permissions, which allows the authenticated members with restricted custom admin role to bypass the restrictions and view the server logs and server config.json file contents.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
信息暴露
Vulnerability Title
Mattermost 安全漏洞
Vulnerability Description
Mattermost是美国Mattermost公司的一个开源协作平台。 Mattermost 6.4.1 版本及更早版本存在安全漏洞,该漏洞源于一个 API 未能正确保护权限,这使得具有受限自定义管理员角色的经过身份验证的成员可以绕过限制并查看服务器日志和服务器 config.json 文件内容。
CVSS Information
N/A
Vulnerability Type
N/A