Description
Mattermost fails to check the Show Full Name option at the /api/v4/teams/TEAM_ID/top/team_members endpoint allowing a member to get the full name of another user even if the Show Full Name option was disabled
No analysis available yet.
Remediation
Vendor Solution
Update Mattermost Server to versions 7.8.10, 8.1.1 or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-57497 | Mattermost fails to check the Show Full Name option at the /api/v4/teams/TEAM_ID/top/team_members endpoint allowing a member to get the full name of another user even if the Show Full Name option was disabled |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
No history.
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-09-05T19:51:13.978Z
Reserved: 2023-09-25T11:43:46.566Z
Link: CVE-2023-5160
Updated: 2024-08-02T07:52:07.474Z
Status : Modified
Published: 2023-10-02T11:15:50.813
Modified: 2024-11-21T08:41:12.280
Link: CVE-2023-5160
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD