Lucene search

K

Slack Security Vulnerabilities

cve
cve

CVE-2019-14366

WP SlackSync plugin through 1.8.5 for WordPress leaks a Slack Access Token in source code. An attacker can obtain a lot of information about the victim's Slack (channels, members, etc.).

7.5CVSS

7.4AI Score

0.002EPSS

2019-11-12 09:15 PM
61
cve
cve

CVE-2020-11498

Slack Nebula through 1.1.0 contains a relative path vulnerability that allows a low-privileged attacker to execute code in the context of the root user via tun_darwin.go or tun_windows.go. A user can also use Nebula to execute arbitrary code in the user's own context, e.g., for user-level persisten...

8.8CVSS

8.9AI Score

0.002EPSS

2020-04-02 11:15 PM
43