Impact
Raven 2.0.0 through 3.0.0 contains a missing authorization flaw that permits any authenticated user to join invite‑only public workspaces by bypassing the can_only_join_via_invite setting. The vulnerability is exercised through the join_workspace API endpoint, allowing an attacker with a standard Raven User role to become a persistent member the workspace and read or post in its public channels. The flaw is an example of unacceptable privilege escalation and is mapped to CWE‑862. The impact is the unauthorized disclosure of workspace data to unauthorized users and potential manipulation or spam of public channels.
Affected Systems
The affected products are The‑Commit‑Company’s Raven software, versions 2.0.0 through 3.0.0. No specific sub‑versions or configuration nuances are listed in the CNA data.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting that there is no publicly confirmed exploitation at this time. However, the attack requires only authentication and the existence of the Invite‑Only flag; an attacker who can authenticate with any Raven User role can exploit the flaw. Because the vulnerability allows read and write access to public channels, it can lead to data leakage or the insertion of unwanted content. The overall risk is moderate, with a simple, cookie‑based exploit path and no additional mitigations required beyond patching or configuration changes.
OpenCVE Enrichment