Mattermost fails to properly validate the permissions when soft deleting a team allowing a team member to soft delete other teams that they are not part of

Advisories
Source ID Title
EUVD EUVD EUVD-2023-2478 Mattermost fails to properly validate the permissions when soft deleting a team allowing a team member to soft delete other teams that they are not part of
Github GHSA Github GHSA GHSA-9hwp-cj7m-wjw4 Mattermost Incorrect Authorization vulnerability
Fixes

Solution

Update Mattermost Server to versions 7.8.10, 8.0.2, 8.1.1 or higher.


Workaround

No workaround given by the vendor.

References
History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2024-09-05T20:00:33.078Z

Reserved: 2023-09-26T09:27:01.462Z

Link: CVE-2023-5195

cve-icon Vulnrichment

Updated: 2024-08-02T07:52:07.770Z

cve-icon NVD

Status : Modified

Published: 2023-09-29T10:15:10.823

Modified: 2024-11-21T08:41:16.720

Link: CVE-2023-5195

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses