Mattermost fails to properly sanitize the user object when updating the username, resulting in the password hash being included in the response body. 

Advisories
Source ID Title
EUVD EUVD EUVD-2023-3022 Mattermost fails to properly sanitize the user object when updating the username, resulting in the password hash being included in the response body. 
Github GHSA Github GHSA GHSA-r67m-mf7v-qp7j Mattermost password hash disclosure vulnerability
Fixes

Solution

Update Mattermost Server to versions 7.8.12, 8.0.4, 8.1.3, 9.0.1 or higher.


Workaround

No workaround given by the vendor.

References
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2024-09-12T19:26:46.796Z

Reserved: 2023-11-06T15:28:44.101Z

Link: CVE-2023-5968

cve-icon Vulnrichment

Updated: 2024-08-02T08:14:25.131Z

cve-icon NVD

Status : Modified

Published: 2023-11-06T16:15:42.897

Modified: 2024-11-21T08:42:53.130

Link: CVE-2023-5968

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.