Description
Mattermost fails to check if hardened mode is enabled when overriding the username and/or the icon when posting a post. If settings allowed integrations to override the username and profile picture when posting, a member could also override the username and icon when making a post even if the Hardened Mode setting was enabled
No analysis available yet.
Remediation
Vendor Solution
Update Mattermost Server to versions 7.8.13, 8.1.4 or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2989 | Mattermost fails to check if hardened mode is enabled when overriding the username and/or the icon when posting a post. If settings allowed integrations to override the username and profile picture when posting, a member could also override the username and icon when making a post even if the Hardened Mode setting was enabled |
Github GHSA |
GHSA-jj46-9cgh-qmfx | Mattermost Improper Access Control vulnerability |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
No history.
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-08-02T21:16:43.979Z
Reserved: 2023-11-22T11:37:35.979Z
Link: CVE-2023-47865
No data.
Status : Modified
Published: 2023-11-27T09:15:32.587
Modified: 2024-11-21T08:30:56.033
Link: CVE-2023-47865
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA