VYPR
Moderate severityNVD Advisory· Published Aug 11, 2023· Updated Oct 11, 2024

Incorrect authorization allows a user manager to update a system admin

CVE-2023-4107

Description

Mattermost fails to properly validate the requesting user permissions when updating a system admin, allowing a user manager to update a system admin's details such as email, first name and last name.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/mattermost/mattermost-server/v6Go
< 7.8.87.8.8
github.com/mattermost/mattermost-server/v6Go
>= 7.9.0, < 7.9.67.9.6
github.com/mattermost/mattermost-server/v6Go
>= 7.10.0, < 7.10.47.10.4

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.