Description
Mattermost fails to validate team membership when a user attempts to access a playbook, allowing a user with permissions to a playbook but no permissions to the team the playbook is on to access and modify the playbook. This can happen if the user was once a member of the team, got permissions to the playbook and was then removed from the team.
No analysis available yet.
Remediation
Vendor Solution
Update Mattermost Server to versions 8.1.6, 9.2.2 or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-58777 | Mattermost fails to validate team membership when a user attempts to access a playbook, allowing a user with permissions to a playbook but no permissions to the team the playbook is on to access and modify the playbook. This can happen if the user was once a member of the team, got permissions to the playbook and was then removed from the team. |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
Mon, 12 May 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2025-05-12T19:28:29.898Z
Reserved: 2023-12-06T08:47:19.482Z
Link: CVE-2023-6547
Updated: 2024-08-02T08:35:14.519Z
Status : Modified
Published: 2023-12-12T09:15:09.857
Modified: 2024-11-21T08:44:04.430
Link: CVE-2023-6547
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD