PT-2023-18354 · Unknown · Mattermost

Whitehattushu

·

Published

2023-04-20

·

Updated

2023-05-02

·

CVE-2023-2193

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Mattermost (affected versions not specified)
Description Mattermost fails to invalidate existing authorization codes when deauthorizing an OAuth2 app, allowing an attacker possessing an authorization code to generate an access token.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2023-2193

Affected Products

Mattermost