Description
Mattermost fails to check if the requesting user is a guest before performing different actions to public playbooks, resulting a guest being able to view, join, edit, export and archive public playbooks.
No analysis available yet.
Remediation
Vendor Solution
Update Mattermost Server to versions 7.8.8, 7.9.5, 7.10.4 or higher. Otherwise, update the Playbooks plugin to version v1.37.0 or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2328 | Mattermost fails to check if the requesting user is a guest before performing different actions to public playbooks, resulting a guest being able to view, join, edit, export and archive public playbooks. |
Github GHSA |
GHSA-p267-jjfq-pphf | Mattermost fails to check if user is a guest before performing actions on public playbooks |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
Tue, 01 Oct 2024 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-10-01T20:21:07.128Z
Reserved: 2023-08-02T15:06:14.198Z
Link: CVE-2023-4106
Updated: 2024-08-02T07:17:11.962Z
Status : Modified
Published: 2023-08-11T07:15:09.853
Modified: 2024-11-21T08:34:24.353
Link: CVE-2023-4106
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA