blob: f237675d12fd246cdccea5b3e84cb7665fc6469a [file] [log] [blame]
id: GO-ID-PENDING
modules:
- module: github.com/mattermost/mattermost-server
non_go_versions:
- introduced: 7.1.0
- fixed: 7.1.6
- introduced: 7.7.0
- fixed: 7.7.2
- introduced: 7.8.0
- fixed: 7.8.1
vulnerable_at: 9.9.0+incompatible
- module: github.com/mattermost/mattermost-server/v6
versions:
- introduced: 6.3.0
vulnerable_at: 6.7.2
summary: Mattermost vulnerable to information disclosure in github.com/mattermost/mattermost-server
description: |-
Mattermost allows an attacker to request a preview of an existing message when
creating a new message via the createPost API call, disclosing the contents of
the linked message.
cves:
- CVE-2023-1777
ghsas:
- GHSA-3wq5-3f56-v5xc
references:
- advisory: https://github.com/advisories/GHSA-3wq5-3f56-v5xc
- web: https://mattermost.com/security-updates/
source:
id: GHSA-3wq5-3f56-v5xc
created: 1999-01-01T00:00:00Z
review_status: REVIEWED