CVE Vulnerabilities

CVE-2023-2281

Published: Apr 25, 2023 | Modified: May 04, 2023
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

When archiving a team, Mattermost fails to sanitize the related Websocket event sent to currently connected clients. This allows the clients to see the name, display name, description, and other data about the archived team.

Affected Software

Name Vendor Start Version End Version
Mattermost_server Mattermost * 7.9.0 (excluding)

References