CVE-2023-3613: Guest accounts invited and added to channels by Welcomebot plugin
Mattermost WelcomeBot plugin fails to to validate the membership status when inviting or adding users to channels allowing guest accounts to be added or invited to channels by default.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mattermost WelcomeBot pluginto a version that resolves this vulnerability.Fixed in 1.3.0 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 7.8.6 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 7.10.3
Event History
Frequently Asked Questions
What is CVE-2023-3613?
CVE-2023-3613 is a vulnerability in the Mattermost WelcomeBot plugin that allows guest accounts to be added or invited to channels without proper validation of their membership status.
How does CVE-2023-3613 affect Mattermost Server?
CVE-2023-3613 affects Mattermost Server versions up to 7.8.6 and versions between 7.9.0 and 7.10.3.
What is the severity of CVE-2023-3613?
CVE-2023-3613 has a severity level of 3.5 (low).
How can I fix CVE-2023-3613?
To fix CVE-2023-3613, update your Mattermost Server to a version that is not affected by the vulnerability.
Where can I find more information about CVE-2023-3613?
You can find more information about CVE-2023-3613 in the security updates page of Mattermost's official website.