Mattermost fails to properly validate permissions when demoting and deactivating a user allowing for a system/user manager to demote / deactivate another manager
References
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published: 2023-09-29T09:28:50.676Z

Updated: 2024-09-05T19:59:54.546Z

Reserved: 2023-09-26T09:03:42.301Z

Link: CVE-2023-5194

cve-icon Vulnrichment

Updated: 2024-08-02T07:52:08.255Z

cve-icon NVD

Status : Analyzed

Published: 2023-09-29T10:15:10.757

Modified: 2023-10-03T17:36:14.853

Link: CVE-2023-5194

cve-icon Redhat

No data.