Description
Mattermost fails to scope the WebSocket response around notified users to a each user separately resulting in the WebSocket broadcasting the information about who was notified about a post to everyone else in the channel.
No analysis available yet.
Remediation
Vendor Solution
Update Mattermost Server to versions 8.1.7, 9.3.0 or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0399 | Mattermost fails to scope the WebSocket response around notified users to a each user separately resulting in the WebSocket broadcasting the information about who was notified about a post to everyone else in the channel. |
Github GHSA |
GHSA-q7rx-w656-fwmv | Mattermost notified all users in the channel when using WebSockets to respond individually |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
Tue, 03 Jun 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2025-06-03T14:45:52.518Z
Reserved: 2023-12-21T08:00:43.425Z
Link: CVE-2023-48732
Updated: 2024-08-02T21:37:54.700Z
Status : Modified
Published: 2024-01-02T10:15:08.487
Modified: 2024-11-21T08:32:20.653
Link: CVE-2023-48732
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA