7.5
CVE-2023-3590
- EPSS 0.36%
- Veröffentlicht 17.07.2023 16:15:10
- Zuletzt bearbeitet 21.11.2024 08:17:37
- Quelle responsibledisclosure@mattermo
- CVE-Watchlists
- Unerledigt
Deleted attachments in Boards remain accessible
Mattermost fails to delete card attachments in Boards, allowing an attacker to access deleted attachments.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mattermost ≫ Mattermost Server Version >= 7.10.0 < 7.10.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.36% | 0.582 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| responsibledisclosure@mattermost.com | 3.1 | 1.6 | 1.4 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
|
CWE-863 Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.