Mattermost fails to check if the requesting user is a guest before performing different actions to public playbooks, resulting a guest being able to view, join, edit, export and archive public playbooks.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2023-2328 | Mattermost fails to check if the requesting user is a guest before performing different actions to public playbooks, resulting a guest being able to view, join, edit, export and archive public playbooks. |
![]() |
GHSA-p267-jjfq-pphf | Mattermost fails to check if user is a guest before performing actions on public playbooks |
Fixes
Solution
Update Mattermost Server to versions 7.8.8, 7.9.5, 7.10.4 or higher. Otherwise, update the Playbooks plugin to version v1.37.0 or higher.
Workaround
No workaround given by the vendor.
References
Link | Providers |
---|---|
https://mattermost.com/security-updates |
![]() ![]() |
History
Tue, 01 Oct 2024 21:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-10-01T20:21:07.128Z
Reserved: 2023-08-02T15:06:14.198Z
Link: CVE-2023-4106

Updated: 2024-08-02T07:17:11.962Z

Status : Modified
Published: 2023-08-11T07:15:09.853
Modified: 2024-11-21T08:34:24.353
Link: CVE-2023-4106

No data.

No data.