First published: Fri Mar 31 2023(Updated: )
When processing an email invite to a private channel on a team, Mattermost fails to validate the inviter's permission to that channel, allowing an attacker to invite themselves to a private channel.
Credit: responsibledisclosure@mattermost.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mattermost Mattermost Server | <7.1.6 | |
Mattermost Mattermost Server | =7.7.1 |
Update Mattermost to version v7.8.0, v7.1.6, v7.7.2, or higher.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-1774 is a vulnerability in Mattermost Server that allows an attacker to invite themselves to a private channel by bypassing permission validation.
CVE-2023-1774 affects Mattermost Server versions up to 7.1.6 and 7.7.1, allowing unauthorized access to private channels.
CVE-2023-1774 has a severity rating of medium with a CVSS score of 5.4.
To fix CVE-2023-1774, update Mattermost Server to a version that is not affected by the vulnerability.
You can find more information about CVE-2023-1774 in the Mattermost security updates page: https://mattermost.com/security-updates/