Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:47227
HistoryMay 29, 2024 - 6:05 a.m.

Improper Access Control

2024-05-2906:05:05
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
1
mattermost
vulnerability
access control
webhook
playbook

4.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

7 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.0%

Mattermost is vulnerable to Improper Access Control. The vulnerability is due to a failure to restrict the audience of the “custom_playbooks_playbook_run_updated” webhook event, allowing a guest on a channel with a linked playbook run to see all details of the playbook run when it is marked as finished.

4.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

7 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.0%

Related for VERACODE:47227