When archiving a team, Mattermost fails to sanitize the related Websocket event sent to currently connected clients. This allows the clients to see the name, display name, description, and other data about the archived team.
References
Link | Resource |
---|---|
https://mattermost.com/security-updates/ | Vendor Advisory |
https://mattermost.com/security-updates/ | Vendor Advisory |
Configurations
History
21 Nov 2024, 07:58
Type | Values Removed | Values Added |
---|---|---|
References | () https://mattermost.com/security-updates/ - Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 3.1 |
Information
Published : 2023-04-25 14:15
Updated : 2024-11-21 07:58
NVD link : CVE-2023-2281
Mitre link : CVE-2023-2281
CVE.ORG link : CVE-2023-2281
JSON object : View
Products Affected
mattermost
- mattermost_server
CWE