Description
Mattermost fails to perform proper authorization in the /plugins/focalboard/api/v2/users endpoint allowing an attacker who is a guest user and knows the ID of another user to get their information (e.g. name, surname, nickname) via Mattermost Boards.
No analysis available yet.
Remediation
Vendor Solution
Update Mattermost Server to versions 9.0.2, 9.1.1, 7.8.13, 8.1.4 or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2916 | Mattermost fails to perform proper authorization in the /plugins/focalboard/api/v2/users endpoint allowing an attacker who is a guest user and knows the ID of another user to get their information (e.g. name, surname, nickname) via Mattermost Boards. |
Github GHSA |
GHSA-85jj-c9jr-9jhx | Mattermost Improper Access Control vulnerability |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
Fri, 11 Oct 2024 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-10-11T17:58:15.479Z
Reserved: 2023-11-20T12:24:12.551Z
Link: CVE-2023-6202
Updated: 2024-08-02T08:21:17.904Z
Status : Modified
Published: 2023-11-27T10:15:08.677
Modified: 2024-11-21T08:43:21.570
Link: CVE-2023-6202
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA