Description
Mattermost webapp fails to validate route parameters in/<TEAM_NAME>/channels/<CHANNEL_NAME> allowing an attacker to perform a client-side path traversal.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Update Mattermost Server to versions 9.1.2, 9.0.3, 8.1.5, 7.8.14 or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-3139 | Mattermost webapp fails to validate route parameters in/<TEAM_NAME>/channels/<CHANNEL_NAME> allowing an attacker to perform a client-side path traversal. |
Github GHSA |
GHSA-7664-hcp7-f497 | Mattermost Injection vulnerability |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
No history.
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-08-02T08:28:21.829Z
Reserved: 2023-12-01T10:06:07.237Z
Link: CVE-2023-6458
No data.
Status : Modified
Published: 2023-12-06T09:15:08.907
Modified: 2024-11-21T08:43:53.947
Link: CVE-2023-6458
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA