CVE-2023-2784: Apps Framework allows install requests from regular members via an internal path
Published Jun 16, 2023
·Updated
Mattermost fails to verify if the requestor is a sysadmin or not, before allowing install requests to the Apps allowing a regular user send install requests to the Apps.
Affected Software
3 affected components
Mattermost Mattermost>=7.8.0<=7.8.4
Mattermost Mattermost>=7.9.0<=7.9.3
Mattermost Mattermost=7.10.0
Remediation
Information
Update Mattermost Server to versions v7.8.5, v7.9.4, v7.10.1 or higher.
Event History
Jun 16, 2023
CVE Published
via MITRE·08:41 AM
Data Sourced
via MITRE·08:41 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this Mattermost vulnerability?
The vulnerability ID is CVE-2023-2784.
2
What is the severity rating of CVE-2023-2784?
The severity rating of CVE-2023-2784 is medium with a score of 6.5.
3
How does Mattermost verify if the requestor is a sysadmin?
Mattermost fails to verify if the requestor is a sysadmin before allowing install requests to the Apps.
4
What versions of Mattermost are affected by CVE-2023-2784?
Versions 7.8.0 to 7.8.4, 7.9.0 to 7.9.3, and 7.10.0 of Mattermost are affected by CVE-2023-2784.
5
How can I fix the issue in Mattermost?
To fix the issue, it is recommended to update Mattermost to a version that is not affected by CVE-2023-2784.