First published: Mon Jul 17 2023(Updated: )
Mattermost fails to disable public Boards after the "Enable Publicly-Shared Boards" configuration option is disabled, resulting in previously-shared public Boards to remain accessible.
Credit: responsibledisclosure@mattermost.com responsibledisclosure@mattermost.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mattermost Mattermost Server | >=7.8.0<7.8.7 | |
Mattermost Mattermost Server | >=7.9.0<7.9.5 | |
Mattermost Mattermost Server | >=7.10.0<7.10.3 |
Update Mattermost Server to versions v7.8.7, v7.9.5, v7.10.3 or higher.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-3586 is a vulnerability in Mattermost that fails to disable public Boards after the "Enable Publicly-Shared Boards" configuration option is disabled, allowing previously-shared public Boards to remain accessible.
CVE-2023-3586 affects Mattermost versions 7.8.0 to 7.8.7, 7.9.0 to 7.9.5, and 7.10.0 to 7.10.3.
The severity of CVE-2023-3586 is medium, with a CVSS score of 5.4.
To fix CVE-2023-3586 in Mattermost, update to a version higher than 7.10.3.
You can find more information about CVE-2023-3586 on the Mattermost website at https://mattermost.com/security-updates.