First published: Wed Mar 22 2023(Updated: )
Mattermost fails to check the "Show Full Name" setting when rendering the result for the /plugins/focalboard/api/v2/users API call, allowing an attacker to learn the full name of a board owner.
Credit: responsibledisclosure@mattermost.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mattermost Mattermost | <7.5.0 |
Update Mattermost to version v7.5.0 or higher.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-1562 is a vulnerability in Mattermost that allows an attacker to learn the full name of a board owner.
CVE-2023-1562 occurs because Mattermost fails to check the "Show Full Name" setting when rendering the result for the /plugins/focalboard/api/v2/users API call.
CVE-2023-1562 affects Mattermost versions up to and excluding 7.5.0.
CVE-2023-1562 has a severity rating of 4.3, which is considered medium.
To fix CVE-2023-1562, upgrade to a version of Mattermost that is 7.5.0 or higher.