CVE-2023-4107: Incorrect authorization allows a user manager to update a system admin
Mattermost fails to properly validate the requesting user permissions when updating a system admin, allowing a user manager to update a system admin's details such as email, first name and last name.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-4107?
CVE-2023-4107 is a vulnerability that allows a user manager to update a system admin's details in Mattermost without proper validation of user permissions.
How does CVE-2023-4107 affect Mattermost?
CVE-2023-4107 affects Mattermost by allowing a user manager to update a system admin's details without proper validation of user permissions.
What is the severity of CVE-2023-4107?
CVE-2023-4107 has a severity rating of medium with a CVSS score of 6.7.
Which versions of Mattermost are affected by CVE-2023-4107?
Mattermost versions 7.10.0 to 7.10.3, 7.9.0 to 7.9.5, and 7.8.0 to 7.8.7 are affected by CVE-2023-4107.
How can CVE-2023-4107 be fixed?
To fix CVE-2023-4107, it is recommended to update Mattermost to version 7.10.4, 7.9.6, or 7.8.8.