CVE-2023-5193: System Role with manage posts permission can read posts of Direct Messages
Mattermost fails to properly check permissions when retrieving a post allowing for a System Role with the permission to manage channels to read the posts of a DM conversation.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-5193?
The severity of CVE-2023-5193 is medium with a severity value of 4.9.
How does Mattermost fail to properly check permissions in CVE-2023-5193?
Mattermost fails to properly check permissions when retrieving a post, allowing a System Role with the permission to manage channels to read the posts of a DM conversation.
Which versions of Mattermost are affected by CVE-2023-5193?
Versions 7.8.10, 8.0.0 to 8.0.1, and 8.1.0 are affected by CVE-2023-5193.
How can I fix CVE-2023-5193?
To fix CVE-2023-5193, update to Mattermost version 7.8.11, 8.0.2, or 8.1.1.
Where can I find more information about CVE-2023-5193?
You can find more information about CVE-2023-5193 at the following references: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2023-5193), [Mattermost Security Updates](https://mattermost.com/security-updates), [GitHub Advisories](https://github.com/advisories/GHSA-h8wh-f7gw-fwpr).