Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-6547
HistoryDec 12, 2023 - 9:15 a.m.

Code injection

2023-12-1209:15:00
PRIOn knowledge base
www.prio-n.com
4
mattermost
code injection
unauthorized access
playbook
team membership validation

7 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

14.0%

Mattermost fails to validate team membership when a user attempts to access a playbook, allowing a user with permissions to a playbook but no permissions to the team the playbook is on to access and modify the playbook. This can happen if the user was once a member of the team, got permissions to the playbook and was then removed from the team.

7 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

14.0%

Related for PRION:CVE-2023-6547