VYPR
Low severityNVD Advisory· Published Aug 11, 2023· Updated Oct 1, 2024

Attachment of deleted message in a thread remains accessible and downloadable

CVE-2023-4105

Description

Mattermost fails to delete the attachments when deleting a message in a thread allowing a simple user to still be able to access and download the attachment of a deleted message

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/mattermost/mattermost-server/v6Go
>= 7.9.0, < 7.9.67.9.6
github.com/mattermost/mattermost-server/v6Go
>= 7.10.0, < 7.10.47.10.4
github.com/mattermost/mattermost-server/v6Go
< 7.8.87.8.8

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.