CVE-2016-11078

MEDIUM

Mattermost Server < 3.0.0 - Unauthenticated Exposure of Sensitive Information via System Console UI

Title source: llm
STIX 2.1

Description

An issue was discovered in Mattermost Server before 3.0.0. It potentially allows attackers to obtain sensitive information (credential fields within config.json) via the System Console UI.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
https://mattermost.com/security-updates/

Scores

CVSS v3 6.5
EPSS 0.0033
EPSS Percentile 55.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-200
Status published
Products (2)
mattermost/mattermost-server 0 - 3.0.0Go
mattermost/mattermost_server < 3.0.0
Published Jun 19, 2020
Tracked Since Feb 18, 2026