CVE-2023-5160
02.10.2023, 11:15
Mattermost fails to check the Show Full Name option at the /api/v4/teams/TEAM_ID/top/team_members endpoint allowinga member to get the full name of another user even if the Show Full Name option was disabledEnginsight
Vendor | Product | Version |
---|---|---|
mattermost | mattermost | 7.0.0 ≤ 𝑥 < 7.8.10 |
mattermost | mattermost | 8.0.0 ≤ 𝑥 < 8.1.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration