/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CVE-2023-6202

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2023-6202

Severity

4.3

Medium

CVSS V3

Description

Mattermost fails to perform proper authorization in the /plugins/focalboard/api/v2/users endpoint allowing an attacker who is a guest user and knows the ID of another user to get their information (e.g. name, surname, nickname) via Mattermost Boards.

References

Affected packages


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing