CVE-2023-47858

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
02/01/2024
Last modified:
08/01/2024

Description

Mattermost fails to properly verify the permissions needed for viewing archived public channels,  allowing a member of one team to get details about the archived public channels of another team via the GET /api/v4/teams//channels/deleted endpoint.<br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* 8.1.7 (excluding)
cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* 9.0.0 (including) 9.0.5 (excluding)
cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* 9.1.0 (including) 9.1.4 (excluding)
cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* 9.2.0 (including) 9.2.3 (excluding)


References to Advisories, Solutions, and Tools