Mattermost WelcomeBot plugin fails to to validate the membership status when inviting or adding users to channels allowing guest accounts to be added or invited to channels by default.
References
Link | Resource |
---|---|
https://mattermost.com/security-updates | Vendor Advisory |
https://mattermost.com/security-updates | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 08:17
Type | Values Removed | Values Added |
---|---|---|
References | () https://mattermost.com/security-updates - Vendor Advisory |
26 Jul 2023, 21:38
Type | Values Removed | Values Added |
---|---|---|
First Time |
Mattermost mattermost Server
Mattermost |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 3.5 |
CWE | CWE-863 | |
CPE | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* | |
References | (MISC) https://mattermost.com/security-updates - Vendor Advisory |
17 Jul 2023, 17:31
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-07-17 16:15
Updated : 2024-11-21 08:17
NVD link : CVE-2023-3613
Mitre link : CVE-2023-3613
CVE.ORG link : CVE-2023-3613
JSON object : View
Products Affected
mattermost
- mattermost_server
CWE
CWE-863
Incorrect Authorization