CVE-2023-2786: Channel commands execution doesn't properly verify permissions
Published Jun 16, 2023
·Updated
Mattermost fails to properly check the permissions when executing commands allowing a member with no permissions to post a message in a channel to actually post it by executing channel commands.
Affected Software
4 affected components
Mattermost Mattermost>=7.1.0<=7.1.9
Mattermost Mattermost>=7.8.0<=7.8.4
Mattermost Mattermost>=7.9.0<=7.9.3
Mattermost Mattermost=7.10.0
Remediation
Information
Update Mattermost Server to versions v7.1.10, v7.8.5, v7.9.4, v.7.10.1 or higher.
Event History
Jun 16, 2023
CVE Published
via MITRE·08:43 AM
Data Sourced
via MITRE·08:43 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this Mattermost vulnerability?
The vulnerability ID for this Mattermost vulnerability is CVE-2023-2786.
2
What software versions are affected by this vulnerability?
Mattermost versions 7.1.0 through 7.1.9, 7.8.0 through 7.8.4, and 7.9.0 through 7.9.3 are affected by this vulnerability.
3
What is the severity of CVE-2023-2786?
The severity of CVE-2023-2786 is medium, with a severity value of 4.3.
4
How does the vulnerability in Mattermost allow unauthorized members to post messages?
The vulnerability in Mattermost allows unauthorized members to post messages by executing channel commands without proper permission checks.
5
How can I fix the CVE-2023-2786 vulnerability in Mattermost?
To fix the CVE-2023-2786 vulnerability in Mattermost, it is recommended to upgrade to a version that is not affected by the vulnerability.