Description
Mattermost allows an attacker to request a preview of an existing message when creating a new message via the createPost API call, disclosing the contents of the linked message.
No analysis available yet.
Remediation
Vendor Solution
Update Mattermost to version v7.8.0, v7.1.6, v7.7.2, or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-0855 | Mattermost allows an attacker to request a preview of an existing message when creating a new message via the createPost API call, disclosing the contents of the linked message. |
Github GHSA |
GHSA-3wq5-3f56-v5xc | Mattermost vulnerable to information disclosure |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates/ |
|
History
Fri, 06 Dec 2024 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-12-06T23:05:19.185Z
Reserved: 2023-03-31T11:34:59.009Z
Link: CVE-2023-1777
Updated: 2024-08-02T05:57:25.203Z
Status : Modified
Published: 2023-03-31T12:15:06.803
Modified: 2024-11-21T07:39:53.243
Link: CVE-2023-1777
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA