CVE-2023-5194: A system/user manager can demote / deactivate another manager
Published Sep 29, 2023
·Updated
Mattermost fails to properly validate permissions when demoting and deactivating a user allowing for a system/user manager to demote / deactivate another manager
Affected Software
5 affected componentsFixes available
go/github.com/mattermost/mattermost-server/v6<7.8.10
7.8.10
go/github.com/mattermost/mattermost/server/v8>=8.0.0<8.0.2
8.0.2
go/github.com/mattermost/mattermost/server/v8=8.1.0
8.1.1
Mattermost Mattermost>=7.0.0<7.8.10
Mattermost Mattermost>=8.0.0<8.1.1
Remediation
Information
Update Mattermost Server to versions 8.1.1, 7.8.10 or higher.
Event History
Sep 29, 2023
CVE Published
via MITRE·09:28 AM
Data Sourced
via MITRE·09:28 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Advisory Published
12:30 PM
Frequently Asked Questions
1
What is CVE-2023-5194?
CVE-2023-5194 is a vulnerability in Mattermost that allows a system/user manager to demote or deactivate another manager without proper permission validation.
2
How does Mattermost fail to validate permissions in CVE-2023-5194?
In CVE-2023-5194, Mattermost fails to properly validate permissions when demoting and deactivating a user, allowing a system/user manager to demote or deactivate another manager.
3
What is the severity of CVE-2023-5194?
The severity of CVE-2023-5194 is low, with a severity value of 2.7.
4
Which versions of Mattermost are affected by CVE-2023-5194?
Mattermost versions 7.8.10, 8.0.0 to 8.0.1, and 8.1.0 are affected by CVE-2023-5194.
5
How can I fix CVE-2023-5194 in Mattermost?
To fix CVE-2023-5194 in Mattermost, upgrade to version 7.8.11, 8.0.2, or 8.1.1.