Mattermost fails to check if an admin user account active after an oauth2 flow is started, allowing an attacker with admin privileges to retain persistent access to Mattermost by obtaining an oauth2 access token while the attacker's account is deactivated.
References
Link | Resource |
---|---|
https://mattermost.com/security-updates/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2023-06-16 09:15
Updated : 2023-06-26 17:47
NVD link : CVE-2023-2788
Mitre link : CVE-2023-2788
CVE.ORG link : CVE-2023-2788
JSON object : View
Products Affected
mattermost
- mattermost