CVE-2023-47865: Username and Icon override can be used by members when Hardened Mode is enabled
Mattermost fails to check if hardened mode is enabled when overriding the username and/or the icon when posting a post. If settings allowed integrations to override the username and profile picture when posting, a member could also override the username and icon when making a post even if the Hardened Mode setting was enabled
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-47865?
CVE-2023-47865 is a vulnerability in Mattermost that allows members to override the username and icon when posting a message, even when Hardened Mode is enabled.
How does CVE-2023-47865 impact Mattermost?
CVE-2023-47865 allows members to bypass the restrictions of Hardened Mode and override the username and icon when making a post.
What is the severity of CVE-2023-47865?
The severity of CVE-2023-47865 is medium with a CVSS score of 4.3.
Which versions of Mattermost are affected by CVE-2023-47865?
Mattermost versions 7.8.13 and earlier, as well as versions 8.1.4 and earlier, are affected by CVE-2023-47865.
How can I fix CVE-2023-47865 in Mattermost?
To fix CVE-2023-47865, update your Mattermost instance to version 7.8.14 or later, or version 8.1.5 or later.