First published: Fri Jun 16 2023(Updated: )
Mattermost Apps Framework fails to verify that a secret provided in the incoming webhook request allowing an attacker to modify the contents of the post sent by the Apps.
Credit: responsibledisclosure@mattermost.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mattermost Mattermost | >=7.8.0<=7.8.4 | |
Mattermost Mattermost | >=7.9.0<=7.9.3 | |
Mattermost Mattermost | =7.10.0 |
Update Mattermost Server to versions Versions 7.8.5, 7.9.4, 7.10.1 or higher.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Mattermost Apps Framework vulnerability is CVE-2023-2783.
CVE-2023-2783 has a severity level of medium with a CVSS score of 4.3.
The affected software for CVE-2023-2783 is Mattermost version 7.8.0 to 7.8.4, 7.9.0 to 7.9.3, and 7.10.0.
An attacker can exploit this vulnerability by providing an incorrect secret in the incoming webhook request, allowing them to modify the contents of the post sent by the Apps.
Yes, Mattermost has released security updates to address CVE-2023-2783. It is recommended to update to the latest version of Mattermost.