Description
Mattermost fails to perform correct authorization checks when creating a playbook action, allowing users without access to the playbook to create playbook actions. If the playbook action created is to post a message in a channel based on specific keywords in a post, some playbook information, like the name, can be leaked.
No analysis available yet.
Remediation
Vendor Solution
Update Mattermost Server to versions 8.1.6, 9.2.2 or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-58941 | Mattermost fails to perform correct authorization checks when creating a playbook action, allowing users without access to the playbook to create playbook actions. If the playbook action created is to post a message in a channel based on specific keywords in a post, some playbook information, like the name, can be leaked. |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
Sat, 24 May 2025 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2025-05-24T10:25:36.906Z
Reserved: 2023-12-12T10:48:31.631Z
Link: CVE-2023-6727
Updated: 2024-08-02T08:35:14.884Z
Status : Modified
Published: 2023-12-12T11:15:07.140
Modified: 2024-11-21T08:44:25.980
Link: CVE-2023-6727
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD