When running in a High Availability configuration, Mattermost fails to sanitize some of the user_updated
andpost_deleted
events broadcast to all users, leading to disclosure of sensitive information to some of the users with currently connected Websocket clients.
Issue Identifier: MMSA-2023-00138
{ "nvd_published_at": "2023-03-31T12:15:00Z", "cwe_ids": [ "CWE-668" ], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2023-04-07T21:23:36Z" }