CVE-2023-3582: Lack of channel membership check when linking a board to a channel
Mattermost fails to verify channel membership when linking a board to a channel allowing a low-privileged authenticated user to link a Board to a private channel they don't have access to,
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in v7.8.7 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in v7.9.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in v7.10.3
Event History
Frequently Asked Questions
What is CVE-2023-3582?
CVE-2023-3582 is a vulnerability in Mattermost that allows a low-privileged authenticated user to link a board to a private channel they don't have access to.
What is the severity of CVE-2023-3582?
The severity of CVE-2023-3582 is medium with a CVSS score of 4.3.
How does CVE-2023-3582 affect Mattermost?
CVE-2023-3582 affects Mattermost versions 7.8.0 to 7.8.7, 7.9.0 to 7.9.5, and 7.10.0 to 7.10.3.
How can I fix CVE-2023-3582 in Mattermost?
To fix CVE-2023-3582 in Mattermost, you should update to a version that is not affected by the vulnerability.
Where can I find more information about CVE-2023-3582?
More information about CVE-2023-3582 can be found at the following link: https://mattermost.com/security-updates