PT-2024-13635 · Mattermost · Mattermost

Published

2024-01-02

·

Updated

2024-06-28

·

CVE-2023-48732

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Mattermost versions prior to v8.1.7
Description The issue arises from Mattermost's failure to scope the WebSocket response around notified users to each user separately. As a result, the WebSocket broadcasts information about who was notified about a post to everyone else in the channel. This could potentially lead to unintended information disclosure.
Recommendations For versions prior to v8.1.7, update to version v8.1.7 or later to resolve the issue. As a temporary workaround, consider disabling the use of WebSockets for individual responses in the channel to minimize the risk of information disclosure. Restrict access to sensitive information and channels to minimize the impact of this issue until a patch is applied.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-MATTERMOST-2023-48732
CVE-2023-48732
GHSA-Q7RX-W656-FWMV
GO-2024-2448

Affected Products

Mattermost