Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update Mattermost Server to versions 7.8.15, 8.1.6, 9.0.4, 9.1.3, 9.2.2 or higher.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-49610 | Mattermost fails to validate if a relative path is passed in /plugins/playbooks/api/v0/telemetry/run/<telem_run_id> as a telemetry run ID, allowing an attacker to use a path traversal payload that points to a different endpoint leading to a CSRF attack. |
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
Sat, 24 May 2025 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2025-05-24T10:26:51.058Z
Reserved: 2023-12-05T08:22:34.306Z
Link: CVE-2023-45316
Updated: 2024-08-02T20:21:15.671Z
Status : Modified
Published: 2023-12-12T09:15:07.740
Modified: 2024-11-21T08:26:43.897
Link: CVE-2023-45316
No data.
OpenCVE Enrichment
No data.
EUVD