Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-2281

Опубликовано: 25 апр. 2023
Источник: redhat

Описание

When archiving a team, Mattermost fails to sanitize the related Websocket event sent to currently connected clients. This allows the clients to see the name, display name, description, and other data about the archived team.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/acm-grafana-rhel8Not affected
Red Hat Advanced Cluster Security 3advanced-cluster-security/rhacs-scanner-db-rhel8Not affected
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-scanner-rhel8Not affected
Red Hat OpenShift Container Platform 4openshift4/ose-grafanaNot affected
Red Hat OpenShift GitOpsopenshift-gitops-1/dex-rhel8Not affected

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=2189631mattermost-server: team data exposure during archival

Связанные уязвимости

CVSS3: 3.1
nvd
почти 3 года назад

When archiving a team, Mattermost fails to sanitize the related Websocket event sent to currently connected clients. This allows the clients to see the name, display name, description, and other data about the archived team.

CVSS3: 3.1
debian
почти 3 года назад

When archiving a team, Mattermost fails to sanitize the related Websoc ...

CVSS3: 3.1
github
почти 3 года назад

When archiving a team, Mattermost fails to sanitize the related Websocket event sent to currently connected clients. This allows the clients to see the name, display name, description, and other data about the archived team.