ZeroHour

CVE-2023-2787

CVSS 3.1
6.5 medium
EPSS
<1%p44
Published
()
Modified
Description

Mattermost fails to check channel membership when accessing message threads, allowing an attacker to access arbitrary posts by using the message threads API.

Vendors
mattermost
Products
mattermost
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.