Lack of restriction to manage group names for freshly demoted guests
Vulnerability Description
Mattermost fails to update the permissions of the current session for a user who was just demoted to guest, allowing freshly demoted guests to change group names.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-50333
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Leandro Chaves (brdoors3)
References
More from Mattermost
View All →Affected Vendor
Mattermost
View all reports →