cbcvebase.
CVE-2023-50333
published 2024-01-02

CVE-2023-50333: Mattermost fails to update the permissions of the current session for a user who was just demoted to guest, allowing freshly demoted guests to change group…

medium4.3CVSS 3.1
AVNACLPRLUINSUCNILAN
Mattermost fails to update the permissions of the current session for a user who was just demoted to guest, allowing freshly demoted guests to change group names.

Affected

3 ranges
VendorProductVersion rangeFixed in
github.commattermost_mattermost_server_v8>= 0 < 8.1.78.1.7
mattermostmattermost<= 9.2.2
mattermostmattermost_server< 8.1.78.1.7