CVE-2023-1777: Information disclosure in linked message previews
Published Mar 31, 2023
·Updated
Mattermost allows an attacker to request a preview of an existing message when creating a new message via the createPost API call, disclosing the contents of the linked message.
Affected Software
9 affected componentsFixes available
Mattermost Mattermost Server<7.1.6
Mattermost Mattermost Server=7.7.1
Mattermost Mattermost Server=7.8.0
go/github.com/mattermost/mattermost-server>=7.1.0<=7.1.5
7.1.6
go/github.com/mattermost/mattermost-server>=7.7.0<=7.7.1
7.7.2
go/github.com/mattermost/mattermost-server=7.8.0
7.8.1
go/github.com/mattermost/mattermost-server/v6>=6.3.0<=6.7.2
7.1.6
go/github.com/mattermost/mattermost-server>=1.4.1-0.20211025164829-f7a8147b825c<1.4.1-0.20230301145909-10be118d99a5
1.4.1-0.20230301145909-10be118d99a5
go/github.com/mattermost/mattermost-server/v6>=6.0.0-20211025164829-f7a8147b825c<6.0.0-20230301145909-10be118d99a5
6.0.0-20230301145909-10be118d99a5
Remediation
Information
Update Mattermost to version v7.8.0, v7.1.6, v7.7.2, or higher.
Event History
Mar 31, 2023
CVE Published
via MITRE·11:35 AM
Data Sourced
via MITRE·11:35 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·12:30 PM
Data Sourced
via GitHub·12:30 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this Mattermost vulnerability?
The vulnerability ID is CVE-2023-1777.
2
What is the severity of CVE-2023-1777?
The severity of CVE-2023-1777 is medium, with a severity value of 5.3.
3
How does CVE-2023-1777 affect Mattermost?
CVE-2023-1777 affects Mattermost by allowing an attacker to request a preview of an existing message when creating a new message via the createPost API call, disclosing the contents of the linked message.
4
Which versions of Mattermost are affected by CVE-2023-1777?
Versions up to and excluding 7.1.6, version 7.7.1, and version 7.8.0 of Mattermost are affected by CVE-2023-1777.
5
How can I fix CVE-2023-1777?
To fix CVE-2023-1777, it is recommended to update Mattermost to a version that is not affected by the vulnerability.