Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Mattermost Desktop App fails to restrict the allow list of domains which NTLM credentials are passed
Vulnerability Description
Mattermost Desktop App versions <=6.1 5.5.13.0 fail to restrict the allow list of domains to which NTLM credentials were forwarded to in the Mattermost Desktop App which allows any user on a server without the image proxy enabled to intercept other users credentials via embedding an image that routes to an external web server. Mattermost Advisory ID: MMSA-2026-00651
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
Vulnerability Type
不充分的凭证保护机制
Vulnerability Title
Mattermost 信任管理问题漏洞
Vulnerability Description
Mattermost是美国Mattermost公司开源的一个开源协作平台。 Mattermost 6.1 5.5.13.0及之前版本存在信任管理问题漏洞,该漏洞源于未能限制允许NTLM凭据转发的域名白名单,可能导致任何未启用图像代理的服务器上的用户通过嵌入路由到外部Web服务器的图像来拦截其他用户的凭据。
CVSS Information
N/A
Vulnerability Type
N/A