CVE-2023-3591: Lack of previous password reset tokens on new token creation
Mattermost fails to invalidate previously generated password reset tokens when a new reset token was created.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in v7.8.7 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in v7.9.5 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in v7.10.3
Event History
Frequently Asked Questions
What is the vulnerability ID for this Mattermost issue?
The vulnerability ID for this Mattermost issue is CVE-2023-3591.
What is the title of this vulnerability?
The title of this vulnerability is 'Mattermost fails to invalidate previously generated password reset tokens when a new reset token was created.'
What is the severity rating of CVE-2023-3591?
CVE-2023-3591 has a severity rating of 8.2, which is considered high.
Which versions of Mattermost Server are affected by CVE-2023-3591?
Versions 7.8.0 to 7.8.7, 7.9.0 to 7.9.5, and 7.10.0 to 7.10.3 of Mattermost Server are affected by CVE-2023-3591.
How can I fix the vulnerability described in CVE-2023-3591?
To fix the vulnerability, it is recommended to update Mattermost Server to a version that includes the security updates listed in the reference link provided.