Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-45316


Mattermost fails to validate if a relative path is passed in /plugins/playbooks/api/v0/telemetry/run/<telem_run_id> as a telemetry run ID, allowing an attacker to use a path traversal payload that points to a different endpoint leading to a CSRF attack.


Published

2023-12-12T09:15:07.740

Last Modified

2024-11-21T08:26:43.897

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.3 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-352
  • Type: Primary
    CWE-22
    CWE-352

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application mattermost mattermost_server ≤ 7.8.14 Yes
Application mattermost mattermost_server ≤ 8.1.5 Yes
Application mattermost mattermost_server ≤ 9.0.3 Yes
Application mattermost mattermost_server ≤ 9.1.2 Yes
Application mattermost mattermost_server ≤ 9.2.1 Yes

References