Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-6547


Mattermost fails to validate team membership when a user attempts to access a playbook, allowing a user with permissions to a playbook but no permissions to the team the playbook is on to access and modify the playbook. This can happen if the user was once a member of the team, got permissions to the playbook and was then removed from the team. 


Published

2023-12-12T09:15:09.857

Last Modified

2024-11-21T08:44:04.430

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 3.7 (LOW)

Weaknesses
  • Type: Secondary
    CWE-284
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application mattermost mattermost_server ≤ 8.1.5 Yes
Application mattermost mattermost_server ≤ 9.2.1 Yes

References