Description
When archiving a team, Mattermost fails to sanitize the related Websocket event sent to currently connected clients. This allows the clients to see the name, display name, description, and other data about the archived team.
No analysis available yet.
Remediation
Vendor Solution
Update Mattermost to version v7.9 or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-33787 | When archiving a team, Mattermost fails to sanitize the related Websocket event sent to currently connected clients. This allows the clients to see the name, display name, description, and other data about the archived team. |
References
History
Fri, 06 Dec 2024 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-12-06T23:04:46.320Z
Reserved: 2023-04-25T13:04:22.071Z
Link: CVE-2023-2281
Updated: 2024-08-02T06:19:14.118Z
Status : Modified
Published: 2023-04-25T14:15:09.423
Modified: 2024-11-21T07:58:18.110
Link: CVE-2023-2281
OpenCVE Enrichment
No data.
Weaknesses
EUVD