← volver
CVE-2021-37864lowCWE-284

Users can view the contents of an archived channel when access is explicitly denied by the system admin

8Vexday Risk Score

Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.

ssvc Trackcvss 2.6epss 0.6%
probabilidad de explotación
0.6%top 53% de las CVE
explotación observada
noninguna fuente lo reporta
Mattermost 6.1 and earlier fails to sufficiently validate permissions while viewing archived channels, which allows authenticated users to view contents of archived channels even when this is denied by system administrators by directly accessing the APIs.
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N
Productos afectados
Mattermost · Mattermost