Description
Mattermost fails to check whether a user is a guest when updating the tasks of a private playbook run allowing a guest to update the tasks of a private playbook run if they know the run ID.
No analysis available yet.
Remediation
Vendor Solution
Update Mattermost Server to versions 9.2.2, 8.1.6, 9.0.4, 9.1.3, 7.8.15 or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-53776 | Mattermost fails to check whether a user is a guest when updating the tasks of a private playbook run allowing a guest to update the tasks of a private playbook run if they know the run ID. |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
No history.
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-08-02T22:01:26.180Z
Reserved: 2023-12-05T08:04:35.043Z
Link: CVE-2023-49874
No data.
Status : Modified
Published: 2023-12-12T09:15:09.310
Modified: 2024-11-21T08:33:58.347
Link: CVE-2023-49874
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD