CVE Vulnerabilities

CVE-2023-5160

Published: Oct 02, 2023 | Modified: Oct 04, 2023
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Mattermost fails to check the Show Full Name option at the /api/v4/teams/TEAM_ID/top/team_members endpoint allowing a member to get the full name of another user even if the Show Full Name option was disabled

Affected Software

Name Vendor Start Version End Version
Mattermost Mattermost 7.0.0 (including) 7.8.10 (excluding)
Mattermost Mattermost 8.0.0 (including) 8.1.1 (excluding)

References