CVE-2023-6202

CVSS V2 None CVSS V3 None
Description
Mattermost fails to perform proper authorization in the /plugins/focalboard/api/v2/users endpoint allowing an attacker who is a guest user and knows the ID of another user to get their information (e.g. name, surname, nickname) via Mattermost Boards.
Overview
  • CVE ID
  • CVE-2023-6202
  • Assigner
  • Mattermost
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2023-11-27T09:12:04.786Z
  • Last Modified Date
  • 2023-11-27T09:12:04.786Z
References
Reference URL Reference Tags
https://mattermost.com/security-updates
History
Created Old Value New Value Data Type Notes
2024-06-25 06:40:00 Added to TrackCVE