VYPR
Unrated severityNVD Advisory· Published Apr 20, 2023· Updated Dec 6, 2024

Oauth authorization codes do not expire when deauthorizing an oauth2 app

CVE-2023-2193

Description

Mattermost fails to invalidate existing authorization codes when deauthorizing an OAuth2 app, allowing an attacker possessing an authorization code to generate an access token.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.