Description
Mattermost fails to properly sanitize the user object when updating the username, resulting in the password hash being included in the response body.
No analysis available yet.
Remediation
Vendor Solution
Update Mattermost Server to versions 7.8.12, 8.0.4, 8.1.3, 9.0.1 or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-3022 | Mattermost fails to properly sanitize the user object when updating the username, resulting in the password hash being included in the response body. |
Github GHSA |
GHSA-r67m-mf7v-qp7j | Mattermost password hash disclosure vulnerability |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
No history.
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-09-12T19:26:46.796Z
Reserved: 2023-11-06T15:28:44.101Z
Link: CVE-2023-5968
Updated: 2024-08-02T08:14:25.131Z
Status : Modified
Published: 2023-11-06T16:15:42.897
Modified: 2024-11-21T08:42:53.130
Link: CVE-2023-5968
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA