2024-01-02 11:00:28 +00:00
{
"id" : "CVE-2023-47858" ,
"sourceIdentifier" : "responsibledisclosure@mattermost.com" ,
"published" : "2024-01-02T10:15:08.117" ,
2024-01-08 21:00:28 +00:00
"lastModified" : "2024-01-08T19:03:08.097" ,
"vulnStatus" : "Analyzed" ,
2024-01-02 11:00:28 +00:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "Mattermost fails to properly verify the permissions needed for viewing archived public channels,\u00a0\u00a0allowing a member of one team to get details about the archived public channels of another team via the\u00a0GET /api/v4/teams/<team-id>/channels/deleted endpoint.\n\n"
2024-01-02 15:00:29 +00:00
} ,
{
"lang" : "es" ,
"value" : "Mattermost no verifica adecuadamente los permisos necesarios para ver los canales p\u00fablicos archivados, lo que permite que un miembro de un equipo obtenga detalles sobre los canales p\u00fablicos archivados de otro equipo a trav\u00e9s de GET /api/v4/teams//channels/deleted endpoint."
2024-01-02 11:00:28 +00:00
}
] ,
"metrics" : {
"cvssMetricV31" : [
2024-01-08 21:00:28 +00:00
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "LOW" ,
"integrityImpact" : "NONE" ,
"availabilityImpact" : "NONE" ,
"baseScore" : 4.3 ,
"baseSeverity" : "MEDIUM"
} ,
"exploitabilityScore" : 2.8 ,
"impactScore" : 1.4
} ,
2024-01-02 11:00:28 +00:00
{
"source" : "responsibledisclosure@mattermost.com" ,
"type" : "Secondary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "LOW" ,
"integrityImpact" : "NONE" ,
"availabilityImpact" : "NONE" ,
"baseScore" : 4.3 ,
"baseSeverity" : "MEDIUM"
} ,
"exploitabilityScore" : 2.8 ,
"impactScore" : 1.4
}
]
} ,
"weaknesses" : [
2024-01-08 21:00:28 +00:00
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "NVD-CWE-Other"
}
]
} ,
2024-01-02 11:00:28 +00:00
{
"source" : "responsibledisclosure@mattermost.com" ,
"type" : "Secondary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-284"
}
]
}
] ,
2024-01-08 21:00:28 +00:00
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "8.1.7" ,
"matchCriteriaId" : "4FFBD373-195D-4481-B87D-5B329DBEC33D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "9.0.0" ,
"versionEndExcluding" : "9.0.5" ,
"matchCriteriaId" : "707E5CDF-AD8D-4D91-8DE8-B32E6E06003B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "9.1.0" ,
"versionEndExcluding" : "9.1.4" ,
"matchCriteriaId" : "689E6CCF-B722-4C95-AAB6-010CC285CF80"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "9.2.0" ,
"versionEndExcluding" : "9.2.3" ,
"matchCriteriaId" : "51A35D8A-9E04-4450-B27E-401B9D43CC12"
}
]
}
]
}
] ,
2024-01-02 11:00:28 +00:00
"references" : [
{
"url" : "https://mattermost.com/security-updates" ,
2024-01-08 21:00:28 +00:00
"source" : "responsibledisclosure@mattermost.com" ,
"tags" : [
"Vendor Advisory"
]
2024-01-02 11:00:28 +00:00
}
]
}