CVE-2023-4108Log File Information Exposure in Mattermost Mattermost-server V6

Severity
7.5HIGHNVD
CNA4.5
EPSS
0.2%
top 63.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 11

Description

Mattermost fails to sanitize post metadata during audit logging resulting in permalinks contents being logged

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

NVDmattermost/mattermost7.8.07.8.8+2
CVEListV5mattermost/mattermost7.8.7+2

🔴Vulnerability Details

3
OSV
Mattermost fails to sanitize post metadata2023-08-11
CVEList
Audit logging fails to sanitize post metadata2023-08-11
GHSA
Mattermost fails to sanitize post metadata2023-08-11
CVE-2023-4108 — Log File Information Exposure | cvebase