CVE-2023-47865
Username and Icon override can be used by members when Hardened Mode is enabled
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Mattermost fails to check if hardened mode is enabled when overriding the username and/or the icon when posting a post. If settings allowed integrations to override the username and profile picture when posting, a member could also override the username and icon when making a post even if the Hardened Mode setting was enabled
Mattermost no verifica si el modo reforzado está habilitado al anular el nombre de usuario y/o el ícono al publicar una publicación. Si la configuración permitía que las integraciones anularan el nombre de usuario y la imagen de perfil al publicar, un miembro también podría anular el nombre de usuario y el ícono al realizar una publicación, incluso si la configuración del Hardened Mode estaba habilitada.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-11-22 CVE Reserved
- 2023-11-27 CVE Published
- 2024-08-02 CVE Updated
- 2024-10-27 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-284: Improper Access Control
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://mattermost.com/security-updates | 2023-12-01 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mattermost Search vendor "Mattermost" | Mattermost Search vendor "Mattermost" for product "Mattermost" | <= 7.8.12 Search vendor "Mattermost" for product "Mattermost" and version " <= 7.8.12" | - |
Affected
| ||||||
Mattermost Search vendor "Mattermost" | Mattermost Search vendor "Mattermost" for product "Mattermost" | >= 8.0.0 <= 8.1.3 Search vendor "Mattermost" for product "Mattermost" and version " >= 8.0.0 <= 8.1.3" | - |
Affected
|