Mattermost fails to redact from audit logs the user password during user creation and the user password hash in other operations if the experimental audit logging configuration was enabled (ExperimentalAuditSettings section in config).
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-24033 | Mattermost fails to redact from audit logs the user password during user creation and the user password hash in other operations if the experimental audit logging configuration was enabled (ExperimentalAuditSettings section in config). |
Fixes
Solution
Update Mattermost to version v7.7.3, v7.8.2, v7.9.1 or higher.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates/ |
|
History
Fri, 06 Dec 2024 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-12-06T23:05:08.457Z
Reserved: 2023-04-04T12:11:43.194Z
Link: CVE-2023-1831
Updated: 2024-08-02T06:05:26.096Z
Status : Modified
Published: 2023-04-17T15:15:06.923
Modified: 2024-11-21T07:39:59.037
Link: CVE-2023-1831
No data.
OpenCVE Enrichment
No data.
EUVD