Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-2281

Опубликовано: 25 апр. 2023
Источник: nvd
CVSS3: 3.1
CVSS3: 4.3
EPSS Низкий

Описание

When archiving a team, Mattermost fails to sanitize the related Websocket event sent to currently connected clients. This allows the clients to see the name, display name, description, and other data about the archived team.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
Версия до 7.9.0 (исключая)

EPSS

Процентиль: 60%
0.00398
Низкий

3.1 Low

CVSS3

4.3 Medium

CVSS3

Дефекты

CWE-200
NVD-CWE-noinfo

Связанные уязвимости

redhat
почти 3 года назад

When archiving a team, Mattermost fails to sanitize the related Websocket event sent to currently connected clients. This allows the clients to see the name, display name, description, and other data about the archived team.

CVSS3: 3.1
debian
почти 3 года назад

When archiving a team, Mattermost fails to sanitize the related Websoc ...

CVSS3: 3.1
github
почти 3 года назад

When archiving a team, Mattermost fails to sanitize the related Websocket event sent to currently connected clients. This allows the clients to see the name, display name, description, and other data about the archived team.

EPSS

Процентиль: 60%
0.00398
Низкий

3.1 Low

CVSS3

4.3 Medium

CVSS3

Дефекты

CWE-200
NVD-CWE-noinfo