CVE-2023-2515
12.05.2023, 09:15
Mattermost fails to restrict a user with permissions to edit other users and to create personal access tokens from elevating their privileges to system adminEnginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| mattermost | mattermost_server | 𝑥 < 7.1.8 |
| mattermost | mattermost_server | 7.2.0 ≤ 𝑥 < 7.7.4 |
| mattermost | mattermost_server | 7.8.0 ≤ 𝑥 < 7.8.3 |
| mattermost | mattermost_server | 7.9.0 ≤ 𝑥 < 7.9.2 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| mattermost | mattermost | 𝑥 ≤ 7.1.7 | CNA |
| mattermost | mattermost | 𝑥 ≤ 7.7.3 | CNA |
| mattermost | mattermost | 𝑥 ≤ 7.8.2 | CNA |
| mattermost | mattermost | 𝑥 ≤ 7.9.1 | CNA |