Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-47858


Mattermost fails to properly verify the permissions needed for viewing archived public channels,  allowing a member of one team to get details about the archived public channels of another team via the GET /api/v4/teams/<team-id>/channels/deleted endpoint.


Published

2024-01-02T10:15:08.117

Last Modified

2024-11-21T08:30:55.513

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.3 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-284
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application mattermost mattermost_server < 8.1.7 Yes
Application mattermost mattermost_server < 9.0.5 Yes
Application mattermost mattermost_server < 9.1.4 Yes
Application mattermost mattermost_server < 9.2.3 Yes

References