CVE-2023-5195: A team member can soft delete other teams that they are not part of
Mattermost fails to properly validate the permissions when soft deleting a team allowing a team member to soft delete other teams that they are not part of
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-5195?
CVE-2023-5195 is a vulnerability in Mattermost where it fails to properly validate permissions when soft deleting a team, allowing a team member to soft delete other teams that they are not part of.
What is the severity of CVE-2023-5195?
CVE-2023-5195 has a severity rating of medium, with a severity value of 6.5.
What is the affected software of CVE-2023-5195?
The affected software for CVE-2023-5195 includes Mattermost server versions up to and excluding 7.8.10, as well as Mattermost server versions between 8.0.0 and 8.0.2 (excluding 8.0.2), and Mattermost server version 8.1.0 (excluding 8.1.1).
How can I fix CVE-2023-5195?
To fix CVE-2023-5195, it is recommended to update to Mattermost server version 7.8.10 or higher, or update to Mattermost server version 8.0.2 or higher, or update to Mattermost server version 8.1.1 or higher.
Where can I find more information about CVE-2023-5195?
For more information about CVE-2023-5195, you can refer to the following resources: NIST NVD (https://nvd.nist.gov/vuln/detail/CVE-2023-5195), Mattermost security updates (https://mattermost.com/security-updates), and GitHub Advisory (https://github.com/advisories/GHSA-9hwp-cj7m-wjw4).