Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Permalink previews displayed for posts in archived channels even if users are disallowed to view archived channels
Vulnerability Description
Mattermost fails to check whether the “Allow users to view archived channels” setting is enabled during permalink previews display, allowing members to view permalink previews of archived channels even if the “Allow users to view archived channels” setting is disabled.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
信息暴露
Vulnerability Title
Mattermost 安全漏洞
Vulnerability Description
Mattermost是美国Mattermost公司的一个开源协作平台。 Mattermost 存在安全漏洞,该漏洞源于无法检查在永久链接预览显示期间是否启用“Allow users to view archived channels”设置,即使禁用“Allow users to view archived channels”设置,也允许成员查看存档频道的永久链接预览。
CVSS Information
N/A
Vulnerability Type
N/A