CVE-2023-49874
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Dec 12, 2023
Updated: Dec 14, 2023
CWE ID 284
Summary
CVE-2023-49874 is a vulnerability affecting Mattermost, an open-source team collaboration platform. This issue arises when Mattermost fails to verify user permissions during the process of updating tasks for private playbook runs. Consequently, unauthorized guests are able to modify the tasks of private playbook runs if they possess the run ID, potentially disrupting workflows and causing unintended changes. This vulnerability poses a significant risk to organizations using Mattermost for critical workflows and requires immediate attention and patching.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share