Mattermost fails to properly validate the permissions when soft deleting a team allowing a team member to soft delete other teams that they are not part of

Advisories
Source ID Title
EUVD EUVD EUVD-2023-2478 Mattermost fails to properly validate the permissions when soft deleting a team allowing a team member to soft delete other teams that they are not part of
Github GHSA Github GHSA GHSA-9hwp-cj7m-wjw4 Mattermost Incorrect Authorization vulnerability
Fixes

Solution

Update Mattermost Server to versions 7.8.10, 8.0.2, 8.1.1 or higher.


Workaround

No workaround given by the vendor.

References
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2024-09-05T20:00:33.078Z

Reserved: 2023-09-26T09:27:01.462Z

Link: CVE-2023-5195

cve-icon Vulnrichment

Updated: 2024-08-02T07:52:07.770Z

cve-icon NVD

Status : Modified

Published: 2023-09-29T10:15:10.823

Modified: 2024-11-21T08:41:16.720

Link: CVE-2023-5195

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.