Mattermost WelcomeBot plugin fails to to validate the membership status when inviting or adding users to channels allowing guest accounts to be added or invited to channels by default.
.This CVE has a CVSS3.1 score of 3.5 and a Base Severity of LOW.
Info | Details |
---|---|
CVE ID | CVE-2023-3613 |
CVE State | PUBLISHED |
BaseScore | 3.5 |
BaseSeverity | LOW |
VectorString | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N |
Version | NA |
References for CVE-2023-3613 :
https://mattermost.com/security-updates
Metric Type | Metric Score |
---|---|
AttackVector(AV) | NETWORK |
AttackComplexity(AC) | LOW |
PrivilegesRequired(PR) | LOW |
UserInteraction(UI) | REQUIRED |
Scope(S) | UNCHANGED |
Confidentiality(C) | LOW |
Availability(A) | NONE |
Integrity(I) | NONE |