Description
When processing an email invite to a private channel on a team, Mattermost fails to validate the inviter's permission to that channel, allowing an attacker to invite themselves to a private channel.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Update Mattermost to version v7.8.0, v7.1.6, v7.7.2, or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-0969 | When processing an email invite to a private channel on a team, Mattermost fails to validate the inviter's permission to that channel, allowing an attacker to invite themselves to a private channel. |
Github GHSA |
GHSA-9hj7-v56g-rhf6 | Mattermost fails to properly authentication inviter's permissions to private channel |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates/ |
|
History
Fri, 06 Dec 2024 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-12-06T23:05:52.973Z
Reserved: 2023-03-31T11:12:43.830Z
Link: CVE-2023-1774
Updated: 2024-08-02T05:57:25.193Z
Status : Modified
Published: 2023-03-31T12:15:06.650
Modified: 2024-11-21T07:39:52.903
Link: CVE-2023-1774
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA