CVE-2023-2788
Last modified
CVE-2023-2788 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Mattermost fails to check if an admin user account active after an oauth2 flow is started, allowing an attacker with admin privileges to retain persistent access to Mattermost by obtaining an oauth2 access token while the attacker's account is deactivated. . EPSS estimates a 0.50% chance of exploitation in the next 30 days.
Description
Mattermost fails to check if an admin user account active after an oauth2 flow is started, allowing an attacker with admin privileges to retain persistent access to Mattermost by obtaining an oauth2 access token while the attacker's account is deactivated.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mattermost | Mattermost | >= 7.1.0, <= 7.1.9 |
| Mattermost | Mattermost | >= 7.8.0, <= 7.8.4 |
| Mattermost | Mattermost | >= 7.9.0, <= 7.9.3 |
| Mattermost | Mattermost | 7.10.0 |
References
- https://mattermost.com/security-updates/Vendor Advisory
- https://mattermost.com/security-updates/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-2788?
How severe is CVE-2023-2788?
How do I fix CVE-2023-2788?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-27873 IBM Aspera Faspex 4.4.2 could allow a remote authenticated …6.5
- CVE-2023-27874IBM Aspera Faspex 4.4.2 is vulnerable to an XML external ent…8.8
- CVE-2023-27875IBM Aspera Faspex 5.0.4 could allow a user to change other u…7.5
- CVE-2023-27876IBM TRIRIGA 4.0 is vulnerable to an XML external entity inje…7.1
- CVE-2023-27877IBM Planning Analytics Cartridge for Cloud Pak for Data 4.0 …7.5
- CVE-2023-27879Improper access control in firmware for some Intel(R) Optane…4.6
- CVE-2023-27881 A user could use the “Upload Resource” functionality to u…9.9
- CVE-2023-27882A heap-based buffer overflow vulnerability exists in the HTT…9.8
- CVE-2023-27886Osprey Pump Controller version 1.01 is vulnerable to an unau…9.8
- CVE-2023-27887Improper initialization in BIOS firmware for some Intel(R) N…4.4
- CVE-2023-27888Cross-site scripting vulnerability in Joruri Gw Ver 3.2.5 an…5.4
- CVE-2023-27889Cross-site request forgery (CSRF) vulnerability in LIQUID SP…8.8
Are you affected by CVE-2023-2788?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
