Description
Mattermost fails to delete the attachments when deleting a message in a thread allowing a simple user to still be able to access and download the attachment of a deleted message
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Update Mattermost Server to versions 7.10.4, 7.9.6, 7.8.8 or higher
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2285 | Mattermost fails to delete the attachments when deleting a message in a thread allowing a simple user to still be able to access and download the attachment of a deleted message |
Github GHSA |
GHSA-g3v6-r8p9-wxg9 | Mattermost fails to correctly delete attachments |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
Tue, 01 Oct 2024 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-10-01T20:31:10.494Z
Reserved: 2023-08-02T14:51:36.949Z
Link: CVE-2023-4105
Updated: 2024-08-02T07:17:12.027Z
Status : Modified
Published: 2023-08-11T07:15:09.740
Modified: 2024-11-21T08:34:24.203
Link: CVE-2023-4105
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA