漏洞标题
泄露删除 direct messages 的用户 ID 和元数据
漏洞描述信息
Mattermost版本9.11.x <= 9.11.6未能从已删除频道端点中过滤掉直接消息(DMs),这使得攻击者可以推断出从已删除的直接消息中手动标记为删除的用户ID和其他元数据。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
漏洞类别
信息暴露
漏洞标题
Leaked User IDs and Metadata of Deleted DMs
漏洞描述信息
Mattermost versions 9.11.x <= 9.11.6 fail to filter out DMs from the deleted channels endpoint which allows an attacker to infer user IDs and other metadata from deleted DMs if someone had manually marked DMs as deleted in the database.
CVSS信息
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
漏洞类别
对因果或异常条件的不恰当检查