CVE-2023-48732 is a medium-severity information disclosure vulnerability affecting Mattermost Server. It allows an authenticated attacker to learn which users were notified about a post in a channel, as the WebSocket broadcasts this information to all channel members instead of only the intended recipients. While the CVSS score is 4.3, indicating low impact, there is currently no public exploit code, active exploitation, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, <= 8.1.6CPE match | cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*:* | ||
< 8.1.7CPE matchmatch criteria | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.