CVE-2023-2515Incorrect Authorization in Mattermost Mattermost-server V6

Severity
8.8HIGHNVD
CNA4.7
EPSS
0.1%
top 65.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 12

Description

Mattermost fails to restrict a user with permissions to edit other users and to create personal access tokens from elevating their privileges to system admin

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages3 packages

NVDmattermost/mattermost_server7.2.07.7.4+3
CVEListV5mattermost/mattermost7.1.7+3

🔴Vulnerability Details

3
GHSA
Mattermost Incorrect Authorization vulnerability2023-05-12
OSV
Mattermost Incorrect Authorization vulnerability2023-05-12
CVEList
Privilege escalation to system admin via personal access tokens2023-05-12
CVE-2023-2515 — Incorrect Authorization | cvebase