Mattermost是美国Mattermost公司的一个开源协作平台。 Mattermost 6.4.1 版本及更早版本存在安全漏洞,该漏洞源于一个 API 未能正确保护权限,这使得具有受限自定义管理员角色的经过身份验证的成员可以绕过限制并查看服务器日志和服务器 config.json 文件内容。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Mattermost | Mattermost | 6.4 ~ 6.4.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-1337 | 4.3 MEDIUM | OOM DoS in Mattermost image proxy |
| CVE-2022-1333 | 3.5 LOW | A specifically drafted Playbook could trigger large amount of webhook requests leading to |
No comments yet