CVE-2023-47858
Details of archived public channels are leaked to members of another team
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Mattermost fails to properly verify the permissions needed for viewing archived public channels, allowing a member of one team to get details about the archived public channels of another team via the GET /api/v4/teams/<team-id>/channels/deleted endpoint.
Mattermost no verifica adecuadamente los permisos necesarios para ver los canales públicos archivados, lo que permite que un miembro de un equipo obtenga detalles sobre los canales públicos archivados de otro equipo a través de GET /api/v4/teams//channels/deleted endpoint.
Mattermost fails to properly verify the permissions needed for viewing archived public channels, allowing a member of one team to get details about the archived public channels of another team via the GET /api/v4/teams/<team-id>/channels/deleted endpoint.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-12-21 CVE Reserved
- 2024-01-02 CVE Published
- 2024-08-02 CVE Updated
- 2025-04-15 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-284: Improper Access Control
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://mattermost.com/security-updates | 2024-01-08 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mattermost Search vendor "Mattermost" | Mattermost Server Search vendor "Mattermost" for product "Mattermost Server" | < 8.1.7 Search vendor "Mattermost" for product "Mattermost Server" and version " < 8.1.7" | - |
Affected
| ||||||
Mattermost Search vendor "Mattermost" | Mattermost Server Search vendor "Mattermost" for product "Mattermost Server" | >= 9.0.0 < 9.0.5 Search vendor "Mattermost" for product "Mattermost Server" and version " >= 9.0.0 < 9.0.5" | - |
Affected
| ||||||
Mattermost Search vendor "Mattermost" | Mattermost Server Search vendor "Mattermost" for product "Mattermost Server" | >= 9.1.0 < 9.1.4 Search vendor "Mattermost" for product "Mattermost Server" and version " >= 9.1.0 < 9.1.4" | - |
Affected
| ||||||
Mattermost Search vendor "Mattermost" | Mattermost Server Search vendor "Mattermost" for product "Mattermost Server" | >= 9.2.0 < 9.2.3 Search vendor "Mattermost" for product "Mattermost Server" and version " >= 9.2.0 < 9.2.3" | - |
Affected
|