← back
CVE-2023-2281

Archiving a team broadcasts unsanitized data over WebSockets

CVSS 3.1 LOWEPSS 0.5%CWE-200
Vexday Risk Score
8Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 3.1EPSS 0.5%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
25 Apr 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
When archiving a team, Mattermost fails to sanitize the related Websocket event sent to currently connected clients. This allows the clients to see the name, display name, description, and other data about the archived team.
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Affected products
Mattermost · Mattermost

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →