Description
Mattermost Apps Framework fails to verify that a secret provided in the incoming webhook request allowing an attacker to modify the contents of the post sent by the Apps.
No analysis available yet.
Remediation
Vendor Solution
Update Mattermost Server to versions Versions 7.8.5, 7.9.4, 7.10.1 or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-1677 | Mattermost Apps Framework fails to verify that a secret provided in the incoming webhook request allowing an attacker to modify the contents of the post sent by the Apps. |
Github GHSA |
GHSA-455c-vqrf-mghr | Mattermost Server Missing Authorization vulnerability |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
Fri, 06 Dec 2024 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-12-06T23:03:51.327Z
Reserved: 2023-05-18T10:17:10.305Z
Link: CVE-2023-2783
Updated: 2024-08-02T06:33:05.566Z
Status : Modified
Published: 2023-06-16T09:15:09.720
Modified: 2024-11-21T07:59:16.937
Link: CVE-2023-2783
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA