OSV 1.4.0 · github-reviewed · 修改于 2021-10-06 21:08
发布时间
2021-09-24 07:11
GitHub 审查时间
2021-09-24 00:23
NVD 发布时间
2021-09-23 01:15
源文件
advisories/github-reviewed/2021/09/GHSA-hv5f-73mr-7vvj/GHSA-hv5f-73mr-7vvj.json
Mattermost 5.38 and earlier fails to sufficiently sanitize clipboard contents, which allows a user-assisted attacker to inject arbitrary web script in product deployments that explicitly disable the default CSP.