Description
Mattermost fails to sanitize ephemeral error messages, allowing an attacker to obtain arbitrary message contents by a specially crafted /groupmsg command.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Update Mattermost to version 7.1.10, 7.8.5, 7.9.4, 7.10.1 or higher
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-34248 | Mattermost fails to sanitize ephemeral error messages, allowing an attacker to obtain arbitrary message contents by a specially crafted /groupmsg command. |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates/ |
|
History
Fri, 06 Dec 2024 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-12-06T23:00:28.026Z
Reserved: 2023-05-18T12:10:39.031Z
Link: CVE-2023-2792
Updated: 2024-08-02T06:33:05.569Z
Status : Modified
Published: 2023-06-16T10:15:09.207
Modified: 2024-11-21T07:59:17.977
Link: CVE-2023-2792
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD