CVE-2023-2515: Privilege escalation to system admin via personal access tokens
Published May 12, 2023
·Updated
Mattermost fails to restrict a user with permissions to edit other users and to create personal access tokens from elevating their privileges to system admin
Affected Software
8 affected componentsFixes available
go/github.com/mattermost/mattermost-server/v6>=7.9.0<7.9.2
7.9.2
go/github.com/mattermost/mattermost-server/v6>=7.8.0<7.8.3
7.8.3
go/github.com/mattermost/mattermost-server/v6>=7.2.0<7.7.4
7.7.4
go/github.com/mattermost/mattermost-server/v6<7.1.8
7.1.8
Mattermost Mattermost Server<7.1.8
Mattermost Mattermost Server>=7.2.0<7.7.4
Mattermost Mattermost Server>=7.8.0<7.8.3
Mattermost Mattermost Server>=7.9.0<7.9.2
Remediation
Information
Update Mattermost Server to versions 7.1.8, 7.7.4, 7.8.3, 7.9.2 or higher.
Event History
May 12, 2023
CVE Published
via MITRE·08:53 AM
Data Sourced
via MITRE·08:53 AM
RemedyDescriptionSeverityWeakness
Advisory Published
09:30 AM
Frequently Asked Questions
1
What is CVE-2023-2515?
CVE-2023-2515 is a vulnerability in Mattermost that allows a user with certain permissions to escalate their privileges to system admin.
2
How does Mattermost restrict user privileges in this vulnerability?
Mattermost fails to restrict a user with permissions to edit other users and create personal access tokens from elevating their privileges to system admin.
3
Which versions of Mattermost are affected by CVE-2023-2515?
The following versions of Mattermost are affected: 7.1.8, 7.2.0 to 7.7.4, 7.8.0 to 7.8.3, and 7.9.0 to 7.9.2.
4
What is the severity of CVE-2023-2515?
CVE-2023-2515 has a severity rating of 8.8 (high).
5
How can I fix CVE-2023-2515?
To fix CVE-2023-2515, upgrade Mattermost to a version that is not affected by the vulnerability.