CVE-2023-5159: A User Manager role with user edit permissions could manage/update bots
Mattermost fails to properly verify the permissions when managing/updating a bot allowing a User Manager role with user edit permissions to manage/update bots.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-5159?
CVE-2023-5159 is a vulnerability in Mattermost that allows a User Manager role with user edit permissions to manage/update bots without proper permission verification.
What is the severity of CVE-2023-5159?
The severity of CVE-2023-5159 is low, with a severity value of 3.8.
How does CVE-2023-5159 affect Mattermost?
CVE-2023-5159 affects Mattermost by allowing users with the User Manager role and user edit permissions to manage/update bots without proper permission verification.
How can I fix CVE-2023-5159 in Mattermost version 7.8.10?
To fix CVE-2023-5159 in Mattermost version 7.8.10, you should update to version 8.0.2 or a later version.
Where can I find more information about CVE-2023-5159?
You can find more information about CVE-2023-5159 on the NIST National Vulnerability Database (NVD) website and the Mattermost security updates page.