Mattermost fails to check the Show Full Name option at the /api/v4/teams/TEAM_ID/top/team_members endpoint allowing a member to get the full name of another user even if the Show Full Name option was disabled
References
Link Resource
https://mattermost.com/security-updates Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: Mattermost

Published: 2023-10-02T10:46:33.153Z

Updated: 2023-10-02T10:46:33.153Z

Reserved: 2023-09-25T11:43:46.566Z


Link: CVE-2023-5160

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-10-02T11:15:50.813

Modified: 2023-10-04T12:18:36.543


Link: CVE-2023-5160

JSON object: View

cve-icon Redhat Information

No data.