When archiving a team, Mattermost fails to sanitize the related Websocket event sent to currently connected clients. This allows the clients to see the name, display name, description, and other data about the archived team.
References
| Link | Resource |
|---|---|
| https://mattermost.com/security-updates/ | Vendor Advisory |
Configurations
History
04 May 2023, 17:37
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Mattermost mattermost Server
Mattermost |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.3 |
| References | (MISC) https://mattermost.com/security-updates/ - Vendor Advisory | |
| CPE | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* | |
| CWE | NVD-CWE-noinfo |
25 Apr 2023, 15:57
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2023-04-25 14:15
Updated : 2023-05-04 17:37
NVD link : CVE-2023-2281
Mitre link : CVE-2023-2281
JSON object : View
Products Affected
mattermost
- mattermost_server
CWE
