MEDIUM
Playbooks access/modification by removed team member
Published Dec 12, 2023
5.4
MEDIUMCVSS 3.1
EPSS 0.32%
Description
Mattermost fails to validate team membership when a user attempts to access a playbook, allowing a user with permissions to a playbook but no permissions to the team the playbook is on to access and modify the playbook. This can happen if the user was once a member of the team, got permissions to the playbook and was then removed from the team.
Affected products
-
- Version 0StatusaffectedConstraints<=8.1.5
- Version 0StatusaffectedConstraints<=9.2.1
- Version 8.1.6StatusunaffectedConstraints-
- Version 9.2.2StatusunaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Mattermost | Mattermost | unaffected |
|
OR
- ≤ 8.1.5
- ≥ 9.2.0 · ≤ 9.2.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Update Mattermost Server to versions 8.1.6, 9.2.2 or higher.
Weaknesses (1)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-58777 Advisory
- https://mattermost.com/security-updates Issue TrackingVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-58777 | Advisory | |
| https://mattermost.com/security-updates | Issue TrackingVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Mattermost
Published Dec 12, 2023
Updated May 12, 2025
Reserved Dec 6, 2023
Link CVE-2023-6547
CISA Vulnrichment
Updated May 12, 2025
ENISA EUVD
EUVD-2023-58777 Assigner Mattermost
Published Dec 12, 2023
Updated May 12, 2025
Exploited since n/a
Link EUVD-2023-58777