Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-1775


When running in a High Availability configuration, Mattermost fails to sanitize some of the user_updated and post_deleted events broadcast to all users, leading to disclosure of sensitive information to some of the users with currently connected Websocket clients.


Published

2023-03-31T12:15:06.700

Last Modified

2024-11-21T07:39:53.017

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.3 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-200
  • Type: Primary
    CWE-668

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application mattermost mattermost_server < 7.1.6 Yes
Application mattermost mattermost_server 7.7.1 Yes

References