CVE Vulnerabilities

CVE-2023-2792

Published: Jun 16, 2023 | Modified: Jun 26, 2023
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Mattermost fails to sanitize ephemeral error messages, allowing an attacker to obtain arbitrary message contents by a specially crafted /groupmsg command.

Affected Software

Name Vendor Start Version End Version
Mattermost Mattermost 7.1.0 (including) 7.1.9 (including)
Mattermost Mattermost 7.8.0 (including) 7.8.4 (including)
Mattermost Mattermost 7.9.0 (including) 7.9.3 (including)
Mattermost Mattermost 7.10.0 (including) 7.10.0 (including)

References