Description
Mattermost fails to properly sanitize the user object when updating the username, resulting in the password hash being included in the response body. 

Published: 2023-11-06
Score: 4.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Update Mattermost Server to versions 7.8.12, 8.0.4, 8.1.3, 9.0.1 or higher.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-3022 Mattermost fails to properly sanitize the user object when updating the username, resulting in the password hash being included in the response body. 
Github GHSA Github GHSA GHSA-r67m-mf7v-qp7j Mattermost password hash disclosure vulnerability
References
History

No history.

Subscriptions

Mattermost Mattermost
cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2024-09-12T19:26:46.796Z

Reserved: 2023-11-06T15:28:44.101Z

Link: CVE-2023-5968

cve-icon Vulnrichment

Updated: 2024-08-02T08:14:25.131Z

cve-icon NVD

Status : Modified

Published: 2023-11-06T16:15:42.897

Modified: 2024-11-21T08:42:53.130

Link: CVE-2023-5968

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses