CVE-2023-2281

LOW

Mattermost Server < 7.9.0 - Unauthorized Sensitive Information Exposure via Websocket Event

Title source: llm
STIX 2.1

Description

When archiving a team, Mattermost fails to sanitize the related Websocket event sent to currently connected clients. This allows the clients to see the name, display name, description, and other data about the archived team.

References (1)

Core 1
Core References

Scores

CVSS v3 3.1
EPSS 0.0026
EPSS Percentile 49.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (1)
mattermost/mattermost_server < 7.9.0
Published Apr 25, 2023
Tracked Since Feb 18, 2026