First published: Fri Sep 29 2023(Updated: )
Mattermost fails to properly check permissions when retrieving a post allowing for a System Role with the permission to manage channels to read the posts of a DM conversation.
Credit: responsibledisclosure@mattermost.com responsibledisclosure@mattermost.com responsibledisclosure@mattermost.com
Affected Software | Affected Version | How to fix |
---|---|---|
go/github.com/mattermost/mattermost-server/v6 | <7.8.10 | 7.8.10 |
go/github.com/mattermost/mattermost/server/v8 | >=8.0.0<8.0.2 | 8.0.2 |
go/github.com/mattermost/mattermost/server/v8 | =8.1.0 | 8.1.1 |
Mattermost Mattermost | >=7.0.0<7.8.10 | |
Mattermost Mattermost | >=8.0.0<8.0.2 | |
Mattermost Mattermost | >=8.1.0<8.1.1 |
Update Mattermost Server to versions 7.8.10, 8.0.2, 8.1.1 or higher
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-5193 is medium with a severity value of 4.9.
Mattermost fails to properly check permissions when retrieving a post, allowing a System Role with the permission to manage channels to read the posts of a DM conversation.
Versions 7.8.10, 8.0.0 to 8.0.1, and 8.1.0 are affected by CVE-2023-5193.
To fix CVE-2023-5193, update to Mattermost version 7.8.11, 8.0.2, or 8.1.1.
You can find more information about CVE-2023-5193 at the following references: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2023-5193), [Mattermost Security Updates](https://mattermost.com/security-updates), [GitHub Advisories](https://github.com/advisories/GHSA-h8wh-f7gw-fwpr).