CVE-2023-1831: User password logged in audit logs
Published Apr 17, 2023
·Updated
Mattermost fails to redact from audit logs the user password during user creation and the user password hash in other operations if the experimental audit logging configuration was enabled (ExperimentalAuditSettings section in config).
Affected Software
3 affected components
Mattermost Mattermost Server<7.7.3
Mattermost Mattermost Server>=7.8.0<7.8.2
Mattermost Mattermost Server=7.9.0
Remediation
Information
Update Mattermost to version v7.7.3, v7.8.2, v7.9.1 or higher.
Event History
Apr 17, 2023
CVE Published
via MITRE·02:21 PM
Data Sourced
via MITRE·02:21 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-1831.
2
What is the title of the vulnerability?
The title of the vulnerability is 'Mattermost fails to redact from audit logs the user password during user creation and the user password hash in other operations'.
3
What is the affected software?
The affected software is Mattermost Server versions up to 7.7.3, versions 7.8.0 to 7.8.2, and version 7.9.0.
4
What is the severity of CVE-2023-1831?
CVE-2023-1831 has a severity value of 7.5 (high).
5
How can I fix the vulnerability?
To fix the vulnerability, update your Mattermost Server to version 7.9.0 or apply the recommended security updates provided by Mattermost.