CVE-2023-45223: Users full name disclosure through Mattermost Boards with Show Full Name Option disabled
Published Nov 27, 2023
·Updated
Mattermost fails to properly validate the "Show Full Name" option in a few endpoints in Mattermost Boards, allowing a member to get the full name of another user even if the Show Full Name option was disabled.
Affected Software
4 affected componentsFixes available
go/github.com/mattermost/mattermost-server/v6<7.8.13
7.8.13
go/github.com/mattermost/mattermost/server/v8<8.1.4
8.1.4
Mattermost Mattermost<=7.8.12
Mattermost Mattermost>=8.0.0<=8.1.3
Remediation
Information
Update Mattermost Server to versions 7.8.13, 8.1.4 or higher.
Event History
Nov 27, 2023
CVE Published
via MITRE·09:06 AM
Data Sourced
via MITRE·09:06 AM
RemedyDescriptionSeverityWeakness
Advisory Published
12:30 PM
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-45223.
2
What is the severity level of CVE-2023-45223?
The severity level of CVE-2023-45223 is medium with a score of 4.3.
3
How does Mattermost Boards disclose users' full names?
Mattermost Boards fails to properly validate the "Show Full Name" option in some endpoints, allowing a member to access the full name of another user even if the option is disabled.
4
Which versions of Mattermost are affected by CVE-2023-45223?
The vulnerable versions of Mattermost are 7.8.13 and versions earlier than 8.1.4.
5
How can I fix the CVE-2023-45223 vulnerability?
To fix the vulnerability, update Mattermost to version 7.8.13 or later for the v6 package, and version 8.1.4 or later for the v8 package.