Lucene search

K
cveMattermostCVE-2023-48732
HistoryJan 02, 2024 - 10:15 a.m.

CVE-2023-48732

2024-01-0210:15:08
CWE-200
Mattermost
web.nvd.nist.gov
21
cve-2023-48732
mattermost
websocket
broadcasting
vulnerability
nvd

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

AI Score

4.3

Confidence

High

EPSS

0

Percentile

14.0%

Mattermost fails to scope the WebSocket response around notified usersย to a each user separately resulting in theย WebSocket broadcasting the information about who was notified about a post to everyone else in the channel.

Affected configurations

Nvd
Node
mattermostmattermost_serverRange<8.1.7
VendorProductVersionCPE
mattermostmattermost_server*cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Mattermost",
    "vendor": "Mattermost",
    "versions": [
      {
        "lessThanOrEqual": "8.1.6",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      },
      {
        "status": "unaffected",
        "version": "8.1.7"
      }
    ]
  }
]

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

AI Score

4.3

Confidence

High

EPSS

0

Percentile

14.0%

Related for CVE-2023-48732