CVE-2023-3587: Inconsistent state in UI after boards permission change by system admin
Mattermost fails to properly show information in the UI, allowing a system admin to modify a board state allowing any user with a valid sharing link to join the board with editor access, without the UI showing the updated permissions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.8.7 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.9.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.10.3
Event History
Frequently Asked Questions
What is CVE-2023-3587?
CVE-2023-3587 is a vulnerability in Mattermost Server that allows a system admin to modify a board state, granting unauthorized access to users with a valid sharing link.
How does Mattermost fail to show information in the UI?
Mattermost fails to display updated permissions in the UI, allowing users with a valid sharing link to join a board with editor access even if their permissions have been modified.
Which versions of Mattermost Server are affected by CVE-2023-3587?
Mattermost Server versions 7.8.0 to 7.8.7 and versions 7.10.0 to 7.10.3 are affected by CVE-2023-3587.
What is the severity of CVE-2023-3587?
CVE-2023-3587 has a severity value of 2.7, which is considered low.
How can I fix the CVE-2023-3587 vulnerability in Mattermost Server?
To fix the CVE-2023-3587 vulnerability, you should update Mattermost Server to a version higher than 7.8.7 or 7.10.3 where the issue is patched.