First published: Fri May 12 2023(Updated: )
Mattermost fails to restrict a user with permissions to edit other users and to create personal access tokens from elevating their privileges to system admin
Credit: responsibledisclosure@mattermost.com responsibledisclosure@mattermost.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mattermost Mattermost Server | <7.1.8 | |
Mattermost Mattermost Server | >=7.2.0<7.7.4 | |
Mattermost Mattermost Server | >=7.8.0<7.8.3 | |
Mattermost Mattermost Server | >=7.9.0<7.9.2 | |
go/github.com/mattermost/mattermost-server/v6 | >=7.9.0<7.9.2 | 7.9.2 |
go/github.com/mattermost/mattermost-server/v6 | >=7.8.0<7.8.3 | 7.8.3 |
go/github.com/mattermost/mattermost-server/v6 | >=7.2.0<7.7.4 | 7.7.4 |
go/github.com/mattermost/mattermost-server/v6 | <7.1.8 | 7.1.8 |
Update Mattermost Server to versions 7.1.8, 7.7.4, 7.8.3, 7.9.2 or higher.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-2515 is a vulnerability in Mattermost that allows a user with certain permissions to escalate their privileges to system admin.
Mattermost fails to restrict a user with permissions to edit other users and create personal access tokens from elevating their privileges to system admin.
The following versions of Mattermost are affected: 7.1.8, 7.2.0 to 7.7.4, 7.8.0 to 7.8.3, and 7.9.0 to 7.9.2.
CVE-2023-2515 has a severity rating of 8.8 (high).
To fix CVE-2023-2515, upgrade Mattermost to a version that is not affected by the vulnerability.