CVE-2023-6547: Playbooks access/modification by removed team member
Mattermost fails to validate team membership when a user attempts to access a playbook, allowing a user with permissions to a playbook but no permissions to the team the playbook is on to access and modify the playbook. This can happen if the user was once a member of the team, got permissions to the playbook and was then removed from the team.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6547?
CVE-2023-6547 is classified as a critical vulnerability due to the potential for unauthorized access to sensitive playbook data.
How do I fix CVE-2023-6547?
To fix CVE-2023-6547, update Mattermost Server to version 9.2.2 or later to ensure proper team membership validation.
Which versions of Mattermost Server are affected by CVE-2023-6547?
CVE-2023-6547 affects Mattermost Server versions up to 8.1.5 and between 9.2.0 to 9.2.1.
What types of attacks could exploit CVE-2023-6547?
CVE-2023-6547 could be exploited by an attacker who previously had team membership and can gain unauthorized access to and modify restricted playbooks.
Is user data at risk due to CVE-2023-6547?
Yes, user data is at risk as unauthorized users could access and modify playbooks they shouldn't have access to, compromising sensitive information.