Mattermost fails to properly check the authorization of POST /api/v4/teams when passing a team override scheme ID in the request, allowing an authenticated attacker with knowledge of a Team Override Scheme ID to create a new team with said team override scheme.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-44234 Mattermost fails to properly check the authorization of POST /api/v4/teams when passing a team override scheme ID in the request, allowing an authenticated attacker with knowledge of a Team Override Scheme ID to create a new team with said team override scheme.
Fixes

Solution

Update Mattermost Server to versions v7.8.5, v7.10.3 or higher.


Workaround

No workaround given by the vendor.

References
History

Mon, 21 Oct 2024 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2024-10-21T19:50:40.857Z

Reserved: 2023-07-10T13:35:18.046Z

Link: CVE-2023-3584

cve-icon Vulnrichment

Updated: 2024-08-02T07:01:55.933Z

cve-icon NVD

Status : Modified

Published: 2023-07-17T16:15:10.553

Modified: 2024-11-21T08:17:36.207

Link: CVE-2023-3584

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.