Unsanitized events sent over Websocket to regular users in a High Availability environment
Vulnerability Description
When running in a High Availability configuration, Mattermost fails to sanitize some of the user_updated and post_deleted events broadcast to all users, leading to disclosure of sensitive information to some of the users with currently connected Websocket clients.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-1775
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Kyriakos Ziakoulis
- Harrison Healey
References
More from Mattermost
View All →Affected Vendor
Mattermost
View all reports →