Mattermost fails to validate team membership when a user attempts to access a playbook, allowing a user with permissions to a playbook but no permissions to the team the playbook is on to access and modify the playbook. This can happen if the user was once a member of the team, got permissions to the playbook and was then removed from the team. 

Advisories
Source ID Title
EUVD EUVD EUVD-2023-58777 Mattermost fails to validate team membership when a user attempts to access a playbook, allowing a user with permissions to a playbook but no permissions to the team the playbook is on to access and modify the playbook. This can happen if the user was once a member of the team, got permissions to the playbook and was then removed from the team. 
Fixes

Solution

Update Mattermost Server to versions 8.1.6, 9.2.2 or higher.


Workaround

No workaround given by the vendor.

References
History

Mon, 12 May 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2025-05-12T19:28:29.898Z

Reserved: 2023-12-06T08:47:19.482Z

Link: CVE-2023-6547

cve-icon Vulnrichment

Updated: 2024-08-02T08:35:14.519Z

cve-icon NVD

Status : Modified

Published: 2023-12-12T09:15:09.857

Modified: 2024-11-21T08:44:04.430

Link: CVE-2023-6547

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.