Description
Mattermost fails to properly check permissions when retrieving a post allowing for a System Role with the permission to manage channels to read the posts of a DM conversation.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Update Mattermost Server to versions 7.8.10, 8.0.2, 8.1.1 or higher
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2520 | Mattermost fails to properly check permissions when retrieving a post allowing for a System Role with the permission to manage channels to read the posts of a DM conversation. |
Github GHSA |
GHSA-h8wh-f7gw-fwpr | Mattermost Incorrect Authorization vulnerability |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
Fri, 20 Sep 2024 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-09-20T16:01:39.785Z
Reserved: 2023-09-26T08:44:07.420Z
Link: CVE-2023-5193
Updated: 2024-08-02T07:52:07.827Z
Status : Modified
Published: 2023-09-29T10:15:10.687
Modified: 2024-11-21T08:41:16.473
Link: CVE-2023-5193
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA