CVE-2023-4478
Summary
| CVE | CVE-2023-4478 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-08-25 10:15:00 UTC |
| Updated | 2023-08-31 17:44:00 UTC |
| Description | Mattermost fails to restrict which parameters' values it takes from the request during signup allowing an attacker to register users as inactive, thus blocking them from later accessing Mattermost without the system admin activating their accounts. |
Risk And Classification
Problem Types: CWE-74
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mattermost | Mattermost Server | All | All | All | All |
| Application | Mattermost | Mattermost Server | 8.0.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| mattermost.com/security-updates | MISC | mattermost.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.