CVE-2023-46701: Inaccessible Post Information Leak via Run Timeline IDOR
Published Dec 12, 2023
·Updated
Mattermost fails to perform authorization checks in the /plugins/playbooks/api/v0/runs/add-to-timeline-dialog endpoint of the Playbooks plugin allowing an attacker to get limited information about a post if they know the post ID
Affected Software
5 affected components
Mattermost Mattermost Server<=7.8.14
Mattermost Mattermost Server>=8.0.0<=8.1.5
Mattermost Mattermost Server>=9.0.0<=9.0.3
Mattermost Mattermost Server>=9.1.1<=9.1.2
Mattermost Mattermost Server>=9.2.0<=9.2.1
Remediation
Information
Update Mattermost Server to versions 8.1.6, 9.0.4, 9.1.3, 9.2.2 or higher.
Event History
Dec 12, 2023
CVE Published
08:19 AM
Data Sourced
08:19 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability of CVE-2023-46701?
Inaccessible Post Information Leak via Run Timeline IDOR vulnerability in Mattermost.
2
How does CVE-2023-46701 impact Mattermost servers?
It allows attackers to access limited information about a post if they know the post ID.
3
Is there a fix available for CVE-2023-46701 vulnerability?
Ensure to apply the security updates provided by Mattermost.