VYPR
Moderate severityNVD Advisory· Published Aug 11, 2023· Updated Oct 1, 2024

A guest user can perform various actions on public playbooks

CVE-2023-4106

Description

Mattermost fails to check if the requesting user is a guest before performing different actions to public playbooks, resulting a guest being able to view, join, edit, export and archive public playbooks.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/mattermost/mattermost-server/v6Go
>= 7.9.0, < 7.9.67.9.6
github.com/mattermost/mattermost-server/v6Go
>= 7.10.0, < 7.10.47.10.4
github.com/mattermost/mattermost-server/v6Go
< 7.8.87.8.8

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.