CVE-2023-3586: Disabling publicly-shared boards does not disable existing publicly available board links
Mattermost fails to disable public Boards after the "Enable Publicly-Shared Boards" configuration option is disabled, resulting in previously-shared public Boards to remain accessible.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.8.7 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.9.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.10.3
Event History
Frequently Asked Questions
What is CVE-2023-3586?
CVE-2023-3586 is a vulnerability in Mattermost that fails to disable public Boards after the "Enable Publicly-Shared Boards" configuration option is disabled, allowing previously-shared public Boards to remain accessible.
How does CVE-2023-3586 affect Mattermost?
CVE-2023-3586 affects Mattermost versions 7.8.0 to 7.8.7, 7.9.0 to 7.9.5, and 7.10.0 to 7.10.3.
What is the severity of CVE-2023-3586?
The severity of CVE-2023-3586 is medium, with a CVSS score of 5.4.
How can I fix CVE-2023-3586 in Mattermost?
To fix CVE-2023-3586 in Mattermost, update to a version higher than 7.10.3.
Where can I find more information about CVE-2023-3586?
You can find more information about CVE-2023-3586 on the Mattermost website at https://mattermost.com/security-updates.