CVE-2023-2515

HIGH8.8EPSS 0.25%

Mattermost Incorrect Authorization vulnerability

Published: 5/12/2023Modified: 12/6/2023
Also known as:GHSA-7g2v-2frm-rg94BIT-mattermost-2023-2515

Description

Mattermost fails to restrict a user with permissions to edit other users and to create personal access tokens from elevating their privileges to system admin

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH8.8CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

References (3)