CVE-2023-5968

MEDIUM4.9EPSS 0.15%

Mattermost password hash disclosure vulnerability

Published: 11/6/2023Modified: 7/22/2025

Description

Mattermost fails to properly sanitize the user object when updating the username, resulting in the password hash being included in the response body. 

Affected packages (4)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM4.9CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

References (6)