Description
Mattermost fails to properly verify the permissions when managing/updating a bot allowing a User Manager role with user edit permissions to manage/update bots.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Update Mattermost Server to versions 7.8.10, 8.1.1 or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2588 | Mattermost fails to properly verify the permissions when managing/updating a bot allowing a User Manager role with user edit permissions to manage/update bots. |
Github GHSA |
GHSA-rp65-jpc7-8h8p | Mattermost Incorrect Authorization vulnerability |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
Fri, 20 Sep 2024 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-09-20T16:02:33.923Z
Reserved: 2023-09-25T11:36:21.829Z
Link: CVE-2023-5159
Updated: 2024-08-02T07:52:07.464Z
Status : Modified
Published: 2023-09-29T10:15:10.530
Modified: 2024-11-21T08:41:12.140
Link: CVE-2023-5159
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA