Show filters
2 Total Results
Displaying 1-2 of 2
Sort by:
Attacker Value
Unknown

CVE-2023-5969

Disclosure Date: November 06, 2023 (last updated November 15, 2023)
Mattermost fails to properly sanitize the request to /api/v4/redirect_location allowing an attacker, sending a specially crafted request to /api/v4/redirect_location, to fill up the memory due to caching large items.
Attacker Value
Unknown

CVE-2023-5968

Disclosure Date: November 06, 2023 (last updated November 15, 2023)
Mattermost fails to properly sanitize the user object when updating the username, resulting in the password hash being included in the response body.