First published: Fri Sep 29 2023(Updated: )
Mattermost fails to properly validate the permissions when soft deleting a team allowing a team member to soft delete other teams that they are not part of
Credit: responsibledisclosure@mattermost.com responsibledisclosure@mattermost.com responsibledisclosure@mattermost.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mattermost Mattermost | >=7.0.0<7.8.10 | |
Mattermost Mattermost | >=8.0.0<8.0.2 | |
Mattermost Mattermost | >=8.1.0<8.1.1 | |
go/github.com/mattermost/mattermost-server/v6 | <7.8.10 | 7.8.10 |
go/github.com/mattermost/mattermost/server/v8 | >=8.0.0<8.0.2 | 8.0.2 |
go/github.com/mattermost/mattermost/server/v8 | =8.1.0 | 8.1.1 |
Update Mattermost Server to versions 7.8.10, 8.0.2, 8.1.1 or higher.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-5195 is a vulnerability in Mattermost where it fails to properly validate permissions when soft deleting a team, allowing a team member to soft delete other teams that they are not part of.
CVE-2023-5195 has a severity rating of medium, with a severity value of 6.5.
The affected software for CVE-2023-5195 includes Mattermost server versions up to and excluding 7.8.10, as well as Mattermost server versions between 8.0.0 and 8.0.2 (excluding 8.0.2), and Mattermost server version 8.1.0 (excluding 8.1.1).
To fix CVE-2023-5195, it is recommended to update to Mattermost server version 7.8.10 or higher, or update to Mattermost server version 8.0.2 or higher, or update to Mattermost server version 8.1.1 or higher.
For more information about CVE-2023-5195, you can refer to the following resources: NIST NVD (https://nvd.nist.gov/vuln/detail/CVE-2023-5195), Mattermost security updates (https://mattermost.com/security-updates), and GitHub Advisory (https://github.com/advisories/GHSA-9hwp-cj7m-wjw4).