Description
Mattermost fails to properly validate the permissions when soft deleting a team allowing a team member to soft delete other teams that they are not part of
No analysis available yet.
Remediation
Vendor Solution
Update Mattermost Server to versions 7.8.10, 8.0.2, 8.1.1 or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2478 | Mattermost fails to properly validate the permissions when soft deleting a team allowing a team member to soft delete other teams that they are not part of |
Github GHSA |
GHSA-9hwp-cj7m-wjw4 | Mattermost Incorrect Authorization vulnerability |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
No history.
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-09-05T20:00:33.078Z
Reserved: 2023-09-26T09:27:01.462Z
Link: CVE-2023-5195
Updated: 2024-08-02T07:52:07.770Z
Status : Modified
Published: 2023-09-29T10:15:10.823
Modified: 2024-11-21T08:41:16.720
Link: CVE-2023-5195
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA