CVE-2023-43754

Mattermost fails to check whether the Allow users to view archived channels setting is enabled during permalink previews display, allowing members to view permalink previews of archived channels even if theAllow users to view archived channels setting is disabled.

ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
MattermostCNA
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 50%
VendorProductVersion
mattermostmattermost
𝑥
≤ 7.8.12
mattermostmattermost
8.0.0 ≤
𝑥
≤ 8.1.3
mattermostmattermost
9.0.0 ≤
𝑥
≤ 9.0.1
mattermostmattermost
9.1.0
𝑥
= Vulnerable software versions