Mattermost fails to check the Show Full Name option at the /api/v4/teams/TEAM_ID/top/team_members endpoint allowing a member to get the full name of another user even if the Show Full Name option was disabled
References
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published: 2023-10-02T10:46:33.153Z

Updated: 2024-09-05T19:51:13.978Z

Reserved: 2023-09-25T11:43:46.566Z

Link: CVE-2023-5160

cve-icon Vulnrichment

Updated: 2024-08-02T07:52:07.474Z

cve-icon NVD

Status : Modified

Published: 2023-10-02T11:15:50.813

Modified: 2024-11-21T08:41:12.280

Link: CVE-2023-5160

cve-icon Redhat

No data.