Description
Mattermost fails to properly validate the requesting user permissions when updating a system admin, allowing a user manager to update a system admin's details such as email, first name and last name.
No analysis available yet.
Remediation
Vendor Solution
Update Mattermost Server to versions 7.8.8, 7.9.6, 7.10.4 or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2228 | Mattermost fails to properly validate the requesting user permissions when updating a system admin, allowing a user manager to update a system admin's details such as email, first name and last name. |
Github GHSA |
GHSA-6xjj-v76v-fwpj | Mattermost does not validate requesting user permissions before updating admin details |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
Fri, 11 Oct 2024 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-10-11T16:52:17.516Z
Reserved: 2023-08-02T15:27:32.294Z
Link: CVE-2023-4107
Updated: 2024-08-02T07:17:12.064Z
Status : Modified
Published: 2023-08-11T07:15:09.963
Modified: 2024-11-21T08:34:24.487
Link: CVE-2023-4107
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA