Unrated severityNVD Advisory· Published Apr 20, 2023· Updated Dec 6, 2024
Oauth authorization codes do not expire when deauthorizing an oauth2 app
CVE-2023-2193
Description
Mattermost fails to invalidate existing authorization codes when deauthorizing an OAuth2 app, allowing an attacker possessing an authorization code to generate an access token.
Affected products
1- Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.