cbcvebase.
CVE-2023-47858
published 2024-01-02

CVE-2023-47858: Mattermost fails to properly verify the permissions needed for viewing archived public channels, allowing a member of one team to get details about the…

medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
Mattermost fails to properly verify the permissions needed for viewing archived public channels, allowing a member of one team to get details about the archived public channels of another team via the GET /api/v4/teams//channels/deleted endpoint.

Affected

7 ranges
VendorProductVersion rangeFixed in
github.commattermost_mattermost-server_v6>= 0 < 7.8.107.8.10
github.commattermost_mattermost_server_v8>= 0 < 8.1.18.1.1
mattermostmattermost<= 9.2.2
mattermostmattermost_server< 8.1.78.1.7
mattermostmattermost_server>= 9.0.0 < 9.0.59.0.5
mattermostmattermost_server>= 9.1.0 < 9.1.49.1.4
mattermostmattermost_server>= 9.2.0 < 9.2.39.2.3
CVE-2023-47858 — Improper Access Control | cvebase