SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-2787

Mattermost fails to check channel membership when accessing message threads, allowing an attacker to access arbitrary posts by using the message threads API.

MEDIUM 6.5EPSS 0.54%

Does this matter?

Lower severity and a low EPSS score (0.54%). Track it; it rarely justifies an emergency change on its own.

Description

Mattermost fails to check channel membership when accessing message threads, allowing an attacker to access arbitrary posts by using the message threads API.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
0.54% probability · 44th percentile
CISA KEV
Not listed
Weakness
CWE-862
Affected
mattermost/mattermost
Source
responsibledisclosure@mattermost.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.