blob: 4f901e410212910f0f90f11c0ba4ebe94c9b2e7e [file] [log] [blame]
id: GO-TEST-ID
modules:
- module: github.com/mattermost/mattermost-server
versions:
- introduced: 7.1.0
fixed: 7.1.6
- introduced: 7.7.0
fixed: 7.7.2
- introduced: 7.8.0
fixed: 7.8.1
- module: github.com/mattermost/mattermost-server/v6
versions:
- introduced: 6.3.0
fixed: 7.1.6
summary: Mattermost vulnerable to information disclosure in github.com/mattermost/mattermost-server
description: |-
Mattermost allows an attacker to request a preview of an existing message when
creating a new message via the createPost API call, disclosing the contents of
the linked message.
cves:
- CVE-2023-1777
ghsas:
- GHSA-3wq5-3f56-v5xc
references:
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2023-1777
- web: https://mattermost.com/security-updates/
notes:
- lint: 'modules[0] "github.com/mattermost/mattermost-server": 6 versions do not exist: 7.1.0, 7.1.6, 7.7.0, 7.7.2, 7.8.0, 7.8.1'
- lint: 'modules[1] "github.com/mattermost/mattermost-server/v6": version 7.1.6 does not exist'