blob: b21f4716f694b60afdebeca561fa6cb886958bb6 [file] [log] [blame]
id: GO-ID-PENDING
modules:
- module: github.com/mattermost/mattermost-server
non_go_versions:
- introduced: 7.1.0
fixed: 7.1.6
- introduced: 7.7.0
fixed: 7.7.2
- introduced: 7.8.0
fixed: 7.8.1
vulnerable_at: 9.8.0+incompatible
- module: github.com/mattermost/mattermost-server/v6
versions:
- introduced: 6.3.0
fixed: 7.1.6
summary: Mattermost vulnerable to information disclosure in github.com/mattermost/mattermost-server
description: |-
Mattermost allows an attacker to request a preview of an existing message when
creating a new message via the createPost API call, disclosing the contents of
the linked message.
cves:
- CVE-2023-1777
ghsas:
- GHSA-3wq5-3f56-v5xc
references:
- advisory: https://github.com/advisories/GHSA-3wq5-3f56-v5xc
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2023-1777
- web: https://mattermost.com/security-updates/
notes:
- fix: 'github.com/mattermost/mattermost-server/v6: could not add vulnerable_at: version 7.1.6 does not exist'
- lint: 'modules[1] "github.com/mattermost/mattermost-server/v6": version 7.1.6 does not exist'
source:
id: GHSA-3wq5-3f56-v5xc
created: 1999-01-01T00:00:00Z
review_status: UNREVIEWED