When running in a High Availability configuration, Mattermost fails to sanitize some of the user_updated and post_deleted events broadcast to all users, leading to disclosure of sensitive information to some of the users with currently connected Websocket clients.
2023-03-31T12:15:06.700
2024-11-21T07:39:53.017
Modified
CVSSv3.1: 4.3 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mattermost | mattermost_server | < 7.1.6 | Yes |
Application | mattermost | mattermost_server | 7.7.1 | Yes |