CVE-2023-47858

Mattermost fails to properly verify the permissions needed for viewing archived public channels,  allowing a member of one team to get details about the archived public channels of another team via the GET /api/v4/teams/<team-id>/channels/deleted endpoint.
References
Link Resource
https://mattermost.com/security-updates Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*

History

08 Jan 2024, 19:03

Type Values Removed Values Added
First Time Mattermost
Mattermost mattermost Server
CWE NVD-CWE-Other
References () https://mattermost.com/security-updates - () https://mattermost.com/security-updates - Vendor Advisory
CPE cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*

02 Jan 2024, 13:47

Type Values Removed Values Added
Summary
  • (es) Mattermost no verifica adecuadamente los permisos necesarios para ver los canales públicos archivados, lo que permite que un miembro de un equipo obtenga detalles sobre los canales públicos archivados de otro equipo a través de GET /api/v4/teams//channels/deleted endpoint.

02 Jan 2024, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-02 10:15

Updated : 2024-01-08 19:03


NVD link : CVE-2023-47858

Mitre link : CVE-2023-47858

CVE.ORG link : CVE-2023-47858


JSON object : View

Products Affected

mattermost

  • mattermost_server
CWE
NVD-CWE-Other CWE-284

Improper Access Control