CVE-2023-47858: Details of archived public channels are leaked to members of another team
Mattermost fails to properly verify the permissions needed for viewing archived public channels, allowing a member of one team to get details about the archived public channels of another team via the GET /api/v4/teams/<team-id>/channels/deleted endpoint.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-47858?
CVE-2023-47858 is considered a critical vulnerability that allows unauthorized access to archived public channels.
How do I fix CVE-2023-47858?
To fix CVE-2023-47858, update Mattermost to version 8.1.1 or later for the v8 branch, or to version 7.8.10 or later for the v6 branch.
Which Mattermost versions are affected by CVE-2023-47858?
CVE-2023-47858 affects Mattermost versions up to 8.1.0 for v8 and up to 7.8.9 for v6.
What type of attack does CVE-2023-47858 facilitate?
CVE-2023-47858 facilitates unauthorized information disclosure by allowing team members to view archived public channels of other teams.
Who is impacted by CVE-2023-47858?
Any Mattermost user in teams configured with archived public channels can be impacted if they have access to the specified API endpoint.