Mattermost fails to check if hardened mode is enabled when overriding the username and/or the icon when posting a post. If settings allowed integrations to override the username and profile picture when posting, a member could also override the username and icon when making a post even if the Hardened Mode setting was enabled

Advisories
Source ID Title
EUVD EUVD EUVD-2023-2989 Mattermost fails to check if hardened mode is enabled when overriding the username and/or the icon when posting a post. If settings allowed integrations to override the username and profile picture when posting, a member could also override the username and icon when making a post even if the Hardened Mode setting was enabled
Github GHSA Github GHSA GHSA-jj46-9cgh-qmfx Mattermost Improper Access Control vulnerability
Fixes

Solution

Update Mattermost Server to versions 7.8.13, 8.1.4 or higher.


Workaround

No workaround given by the vendor.

References
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2024-08-02T21:16:43.979Z

Reserved: 2023-11-22T11:37:35.979Z

Link: CVE-2023-47865

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-11-27T09:15:32.587

Modified: 2024-11-21T08:30:56.033

Link: CVE-2023-47865

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.