ZeroHour

CVE-2023-5968

CVSS 3.1
4.9 medium
EPSS
<1%p42
Published
()
Modified
Description

Mattermost fails to properly sanitize the user object when updating the username, resulting in the password hash being included in the response body.

Vendors
mattermost
Products
mattermost
Weakness
CWE-200, CWE-116
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.