CVE-2023-49874: IDOR when updating the tasks of a private playbook run
Published Dec 12, 2023
·Updated
Mattermost fails to check whether a user is a guest when updating the tasks of a private playbook run allowing a guest to update the tasks of a private playbook run if they know the run ID.
Affected Software
5 affected components
Mattermost Mattermost Server<=7.8.14
Mattermost Mattermost Server>=8.0.0<=8.1.5
Mattermost Mattermost Server>=9.0.0<=9.0.3
Mattermost Mattermost Server>=9.1.1<=9.1.2
Mattermost Mattermost Server>=9.2.0<=9.2.1
Remediation
Information
Update Mattermost Server to versions 9.2.2, 8.1.6, 9.0.4, 9.1.3, 7.8.15 or higher.
Event History
Dec 12, 2023
CVE Published
08:17 AM
Data Sourced
08:17 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-49874?
CVE-2023-49874 is considered a medium severity vulnerability.
2
How do I fix CVE-2023-49874?
To fix CVE-2023-49874, update Mattermost Server to version 7.8.15 or later, or to a version in the 8.1.6 or 9.0.4 series and above.
3
Who is affected by CVE-2023-49874?
CVE-2023-49874 affects all users of Mattermost Server versions up to 7.8.14 and various versions from 8.0.0 to 9.2.1.
4
What are the implications of CVE-2023-49874?
CVE-2023-49874 allows guest users to modify tasks in a private playbook run if they have the run ID, leading to unauthorized access.
5
Is there a workaround for CVE-2023-49874?
There is currently no confirmed workaround for CVE-2023-49874; upgrading to a patched version is recommended.