CVE-2023-6727Sensitive Information Exposure in Mattermost

Severity
4.3MEDIUMNVD
CNA3.1OSV6.5
EPSS
0.3%
top 44.26%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 12
Latest updateApr 11

Description

Mattermost fails to perform correct authorization checks when creating a playbook action, allowing users without access to the playbook to create playbook actions. If the playbook action created is to post a message in a channel based on specific keywords in a post, some playbook information, like the name, can be leaked.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages3 packages

CVEListV5mattermost/mattermost8.1.5+1
NVDmattermost/mattermost_server9.2.09.2.1+1
Ubuntumozilla/nss< 2:3.98-0ubuntu0.20.04.2+1

🔴Vulnerability Details

3
OSV
nss regression2024-04-11
CVEList
Leak Inaccessible Playbook Information via Channel Action IDOR2023-12-12
GHSA
GHSA-7g28-89m4-f55f: Mattermost fails to perform correct authorization checks when creating a playbook action, allowing users without access to the playbook to create play2023-12-12
CVE-2023-6727 — Sensitive Information Exposure | cvebase