First published: Mon Nov 27 2023(Updated: )
Mattermost fails to properly validate the "Show Full Name" option in a few endpoints in Mattermost Boards, allowing a member to get the full name of another user even if the Show Full Name option was disabled.
Credit: responsibledisclosure@mattermost.com responsibledisclosure@mattermost.com
Affected Software | Affected Version | How to fix |
---|---|---|
go/github.com/mattermost/mattermost-server/v6 | <7.8.13 | 7.8.13 |
go/github.com/mattermost/mattermost/server/v8 | <8.1.4 | 8.1.4 |
Mattermost Mattermost | <=7.8.12 | |
Mattermost Mattermost | >=8.0.0<=8.1.3 |
Update Mattermost Server to versions 7.8.13, 8.1.4 or higher.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2023-45223.
The severity level of CVE-2023-45223 is medium with a score of 4.3.
Mattermost Boards fails to properly validate the "Show Full Name" option in some endpoints, allowing a member to access the full name of another user even if the option is disabled.
The vulnerable versions of Mattermost are 7.8.13 and versions earlier than 8.1.4.
To fix the vulnerability, update Mattermost to version 7.8.13 or later for the v6 package, and version 8.1.4 or later for the v8 package.