CVE-2023-2791: Playbooks lets you edit arbitrary posts
When creating a playbook run via the /dialog API, Mattermost fails to validate all parameters, allowing an authenticated attacker to edit an arbitrary channel post.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-2791?
CVE-2023-2791 is a vulnerability in Mattermost that allows an authenticated attacker to edit an arbitrary channel post when creating a playbook run via the /dialog API.
How does CVE-2023-2791 affect Mattermost?
CVE-2023-2791 affects Mattermost versions 7.7.0 to 7.7.3, 7.8.0 to 7.8.2, 7.9.0 to 7.9.1, and 7.10.0.
What is the severity of CVE-2023-2791?
CVE-2023-2791 has a severity rating of medium (4.3).
How can an attacker exploit CVE-2023-2791?
An attacker can exploit CVE-2023-2791 by creating a malicious playbook run via the /dialog API and gaining access to edit arbitrary channel posts.
Is there a fix for CVE-2023-2791?
Yes, Mattermost has released security updates to address CVE-2023-2791. It is recommended to upgrade to the latest version to mitigate the vulnerability.