ZeroHour

CVE-2023-2193

CVSS 3.1
9.1 critical
EPSS
<1%p46
Published
()
Modified
Description

Mattermost fails to invalidate existing authorization codes when deauthorizing an OAuth2 app, allowing an attacker possessing an authorization code to generate an access token.

Vendors
mattermost
Products
mattermost
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.