First published: Mon Jul 17 2023(Updated: )
Mattermost fails to properly check the authorization of POST /api/v4/teams when passing a team override scheme ID in the request, allowing an authenticated attacker with knowledge of a Team Override Scheme ID to create a new team with said team override scheme.
Credit: responsibledisclosure@mattermost.com responsibledisclosure@mattermost.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mattermost Mattermost Server | >=7.8.0<7.8.5 | |
Mattermost Mattermost Server | >=7.10.0<7.10.3 |
Update Mattermost Server to versions v7.8.5, v7.10.3 or higher.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-3584 is a vulnerability in Mattermost which allows an authenticated attacker to create a new team by bypassing authorization checks.
Mattermost fails to properly check the authorization in POST /api/v4/teams when passing a team override scheme ID in the request.
The vulnerability in Mattermost allows an authenticated attacker with knowledge of a Team Override Scheme ID to create a new team with said team override scheme.
Mattermost Server versions 7.8.0 to 7.8.5 and 7.10.0 to 7.10.3 are affected by this vulnerability.
The severity of CVE-2023-3584 is low, with a CVSSv3 score of 3.1.