CVE-2023-1775

MEDIUM6.5EPSS 0.31%

Mattermost vulnerable to information disclosure

Published: 3/31/2023Modified: 12/6/2023
Also known as:GHSA-8jhh-3jf2-pfwrBIT-mattermost-2023-1775

Description

When running in a High Availability configuration, Mattermost fails to sanitize some of the `user_updated` and` post_deleted` events broadcast to all users, leading to disclosure of sensitive information to some of the users with currently connected Websocket clients. [Issue Identifier](https://mattermost.com/security-updates/): MMSA-2023-00138

Affected packages (4)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM6.5CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

References (4)