Description
When running in a High Availability configuration, Mattermost fails to sanitize some of the user_updated and post_deleted events broadcast to all users, leading to disclosure of sensitive information to some of the users with currently connected Websocket clients.
No analysis available yet.
Remediation
Vendor Solution
Update Mattermost to version v7.8.0, v7.1.6, v7.7.2, or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-0949 | When running in a High Availability configuration, Mattermost fails to sanitize some of the user_updated and post_deleted events broadcast to all users, leading to disclosure of sensitive information to some of the users with currently connected Websocket clients. |
Github GHSA |
GHSA-8jhh-3jf2-pfwr | Mattermost vulnerable to information disclosure |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates/ |
|
History
Fri, 06 Dec 2024 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-12-06T23:05:41.615Z
Reserved: 2023-03-31T11:26:09.249Z
Link: CVE-2023-1775
Updated: 2024-08-02T05:57:25.258Z
Status : Modified
Published: 2023-03-31T12:15:06.700
Modified: 2024-11-21T07:39:53.017
Link: CVE-2023-1775
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA