Description
Mattermost fails to properly show information in the UI, allowing a system admin to modify a board state allowing any user with a valid sharing link to join the board with editor access, without the UI showing the updated permissions.
No analysis available yet.
Remediation
Vendor Solution
Update Mattermost Server to versions 7.8.7, 7.9.5, 7.10.3 or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-44237 | Mattermost fails to properly show information in the UI, allowing a system admin to modify a board state allowing any user with a valid sharing link to join the board with editor access, without the UI showing the updated permissions. |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
Tue, 22 Oct 2024 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-10-22T13:40:42.183Z
Reserved: 2023-07-10T14:01:18.080Z
Link: CVE-2023-3587
Updated: 2024-08-02T07:01:56.922Z
Status : Modified
Published: 2023-07-17T16:15:10.780
Modified: 2024-11-21T08:17:36.643
Link: CVE-2023-3587
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD