Mattermost fails to check the Show Full Name option at the /api/v4/teams/TEAM_ID/top/team_members endpoint allowing a member to get the full name of another user even if the Show Full Name option was disabled
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://mattermost.com/security-updates |
![]() ![]() ![]() |
History
No history.

Status: PUBLISHED
Assigner: Mattermost
Published: 2023-10-02T10:46:33.153Z
Updated: 2024-09-05T19:51:13.978Z
Reserved: 2023-09-25T11:43:46.566Z
Link: CVE-2023-5160

Updated: 2024-08-02T07:52:07.474Z

Status : Modified
Published: 2023-10-02T11:15:50.813
Modified: 2024-11-21T08:41:12.280
Link: CVE-2023-5160

No data.