Incorrect Authorization Affecting github.com/mattermost/mattermost-server package, versions <9.1.0-rc1


Severity

Recommended
0.0
low
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.03% (9th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMMATTERMOSTMATTERMOSTSERVER-5925837
  • published29 Sept 2023
  • disclosed29 Sept 2023
  • creditPyae Phyo

Introduced: 29 Sep 2023

CVE-2023-5159  (opens in a new tab)
CWE-863  (opens in a new tab)

How to fix?

Upgrade github.com/mattermost/mattermost-server to version 9.1.0-rc1 or higher.

Overview

github.com/mattermost/mattermost-server is an open source Slack-alternative in Golang and React.

Affected versions of this package are vulnerable to Incorrect Authorization when managing or updating a bot. An attacker can manipulate bot settings by exploiting the improper verification of permissions.

Note:

This is only exploitable if the attacker has a User Manager role with user edit permissions.

CVSS Base Scores

version 3.1