cbcvebase.
CVE-2023-1777
published 2023-03-31

CVE-2023-1777: Mattermost allows an attacker to request a preview of an existing message when creating a new message via the createPost API call, disclosing the contents of…

medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
Mattermost allows an attacker to request a preview of an existing message when creating a new message via the createPost API call, disclosing the contents of the linked message.

Affected

10 ranges
VendorProductVersion rangeFixed in
github.commattermost_mattermost-server>= 1.4.1-0.20211025164829-f7a8147b825c < 1.4.1-0.20230301145909-10be118d99a51.4.1-0.20230301145909-10be118d99a5
github.commattermost_mattermost-server>= 7.1.0 < 7.1.67.1.6
github.commattermost_mattermost-server>= 7.7.0 < 7.7.27.7.2
github.commattermost_mattermost-server>= 7.8.0 < 7.8.17.8.1
github.commattermost_mattermost-server_v6>= 6.0.0-20211025164829-f7a8147b825c < 6.0.0-20230301145909-10be118d99a56.0.0-20230301145909-10be118d99a5
github.commattermost_mattermost-server_v6>= 6.3.0 < 7.1.67.1.6
mattermostmattermost6.3.0 – 7.7.1
mattermostmattermost_server< 7.1.67.1.6
mattermostmattermost_server
mattermostmattermost_server