Unrated severityNVD Advisory· Published Jun 16, 2023· Updated Dec 6, 2024
Deactivated user can retain access using oauth2 api
CVE-2023-2788
Description
Mattermost fails to check if an admin user account active after an oauth2 flow is started, allowing an attacker with admin privileges to retain persistent access to Mattermost by obtaining an oauth2 access token while the attacker's account is deactivated.
Affected products
1- Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.