Mattermost fails to redact from audit logsĀ the user password during user creation and the user password hash in other operations if the experimental audit logging configuration was enabled (ExperimentalAuditSettings section in config).
2023-04-17T15:15:06.923
2024-11-21T07:39:59.037
Modified
CVSSv3.1: 7.2 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mattermost | mattermost_server | < 7.7.3 | Yes |
Application | mattermost | mattermost_server | < 7.8.2 | Yes |
Application | mattermost | mattermost_server | 7.9.0 | Yes |