Description
Mattermost fails to perform authorization checks in the /plugins/playbooks/api/v0/runs/add-to-timeline-dialog endpoint of the Playbooks plugin allowing an attacker to get limited information about a post if they know the post ID
No analysis available yet.
Remediation
Vendor Solution
Update Mattermost Server to versions 8.1.6, 9.0.4, 9.1.3, 9.2.2 or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-50887 | Mattermost fails to perform authorization checks in the /plugins/playbooks/api/v0/runs/add-to-timeline-dialog endpoint of the Playbooks plugin allowing an attacker to get limited information about a post if they know the post ID |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
No history.
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-08-02T20:53:20.920Z
Reserved: 2023-12-05T08:22:34.302Z
Link: CVE-2023-46701
No data.
Status : Modified
Published: 2023-12-12T09:15:08.180
Modified: 2024-11-21T08:29:06.583
Link: CVE-2023-46701
No data.
OpenCVE Enrichment
No data.
EUVD