Total vulnerabilities in the database
When running in a High Availability configuration, Mattermost fails to sanitize some of the user_updated and post_deleted events broadcast to all users, leading to disclosure of sensitive information to some of the users with currently connected Websocket clients.
Software | From | Fixed in |
---|---|---|
mattermost / mattermost_server | 7.7.1 | 7.7.1.x |
mattermost / mattermost_server | - | 7.1.6 |
![]() |
3.3.0 | 7.1.6 |
![]() |
7.7.0 | 7.7.2 |
![]() |
7.1.0 | 7.1.6 |
![]() |
5.0.0 | 7.1.6 |
![]() |
6.0.0 | 7.1.6 |