CVE-2023-2792: Ephemeral messages return private channel contents in permalink previews
Published Jun 16, 2023
·Updated
Mattermost fails to sanitize ephemeral error messages, allowing an attacker to obtain arbitrary message contents by a specially crafted /groupmsg command.
Affected Software
4 affected components
Mattermost Mattermost>=7.1.0<=7.1.9
Mattermost Mattermost>=7.8.0<=7.8.4
Mattermost Mattermost>=7.9.0<=7.9.3
Mattermost Mattermost=7.10.0
Remediation
Information
Update Mattermost to version 7.1.10, 7.8.5, 7.9.4, 7.10.1 or higher
Event History
Jun 16, 2023
CVE Published
via MITRE·09:01 AM
Data Sourced
via MITRE·09:01 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-2792?
CVE-2023-2792 is a vulnerability in Mattermost that allows an attacker to obtain arbitrary message contents.
2
What is the severity level of CVE-2023-2792?
CVE-2023-2792 has a severity level of medium.
3
Which versions of Mattermost are affected by CVE-2023-2792?
Mattermost versions 7.1.0 to 7.1.9, 7.8.0 to 7.8.4, 7.9.0 to 7.9.3, and 7.10.0 are affected by CVE-2023-2792.
4
How can an attacker exploit CVE-2023-2792?
An attacker can exploit CVE-2023-2792 by using a specially crafted /groupmsg command to obtain arbitrary message contents.
5
How can I fix CVE-2023-2792?
To fix CVE-2023-2792, it is recommended to update to a version of Mattermost that is not affected by the vulnerability.