App Framework does not checks for the secret provided in the incoming webhook request
CVE-2023-2783
4.3MEDIUM
What is CVE-2023-2783?
Mattermost Apps Framework fails to verify that a secret provided in the incoming webhook request allowing an attacker to modify the contents of the post sent by the Apps.
Affected Version(s)
Mattermost App Framework 0 <= 7.8.4
Mattermost App Framework 0 <= 7.9.3
Mattermost App Framework 7.10.0