CVE-2023-2783
App Framework does not checks for the secret provided in the incoming webhook request
Mattermost Apps Framework fails to verify that a secret provided in the incoming webhook request allowing an attacker to modify the contents of the post sent by the Apps.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Affected products
Mattermost · Mattermost App FrameworkWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
https://mattermost.com/security-updates