Description
Mattermost fails to invalidate existing authorization codes when deauthorizing an OAuth2 app, allowing an attacker possessing an authorization code to generate an access token.
No analysis available yet.
Remediation
Vendor Solution
Update Mattermost to version v7.10, v7.9.3, v7.8.4, v7.7.5, v7.1.9 or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-33708 | Mattermost fails to invalidate existing authorization codes when deauthorizing an OAuth2 app, allowing an attacker possessing an authorization code to generate an access token. |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates/ |
|
History
Fri, 06 Dec 2024 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-12-06T23:04:57.399Z
Reserved: 2023-04-20T08:16:27.253Z
Link: CVE-2023-2193
Updated: 2024-08-02T06:12:20.643Z
Status : Modified
Published: 2023-04-20T09:15:10.603
Modified: 2024-11-21T07:58:07.110
Link: CVE-2023-2193
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD