CVE-2023-43754

Source
https://cve.org/CVERecord?id=CVE-2023-43754
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-43754.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-43754
Aliases
Related
Published
2023-11-27T09:11:13.283Z
Modified
2026-08-12T03:51:33.129833716Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Permalink previews displayed for posts in archived channels even if users are disallowed to view archived channels
Details

Mattermost fails to check whether the  “Allow users to view archived channels”  setting is enabled during permalink previews display, allowing members to view permalink previews of archived channels even if the “Allow users to view archived channels” setting is disabled. 

Database specific
{
    "cwe_ids": [
        "CWE-200"
    ],
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "last_affected": "7.8.12"
                },
                {
                    "last_affected": "8.1.3"
                },
                {
                    "last_affected": "9.0.1"
                },
                {
                    "last_affected": "9.1.0"
                }
            ]
        }
    ],
    "cna_assigner": "Mattermost",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/43xxx/CVE-2023-43754.json"
}
References

Affected packages

Git / github.com/mattermost/mattermost

Affected ranges

Type
GIT
Repo
https://github.com/mattermost/mattermost
Events
Database specific
Show details
{
    "cpe": [
        "cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*:*",
        "cpe:2.3:a:mattermost:mattermost:9.1.0:*:*:*:*:*:*:*"
    ],
    "source": [
        "CPE_RANGE",
        "CPE_STRING"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "7.8.12"
        },
        {
            "introduced": "8.0.0"
        },
        {
            "last_affected": "8.1.3"
        },
        {
            "introduced": "9.0.0"
        },
        {
            "last_affected": "9.0.1"
        },
        {
            "introduced": "9.1.0"
        },
        {
            "last_affected": "9.1.0"
        }
    ]
}

Affected versions

9.*
9.1.0
@mattermost/client@8.*
@mattermost/client@8.1.1
@mattermost/client@9.*
@mattermost/client@9.0.0
@mattermost/client@9.1.0
@mattermost/types@8.*
@mattermost/types@8.1.1
@mattermost/types@9.*
@mattermost/types@9.0.0
@mattermost/types@9.1.0
Other
cloud-2022-07-20-1
cloud-2022-08-10-1
cloud-2022-09-08-1
cloud-2022-10-06-1
cloud-2022-11-11-1
cloud-2022-11-24-1
cloud-2023-01-26-1
cloud-2023-07-26-1
server/public/v0.*
server/public/v0.0.5
v0.*
v0.5.0
v4.*
v4.10.0-rc1
v4.2.0-rc1
v4.3.0-rc1
v4.4.0-rc1
v4.5.0-rc1
v4.6.0-rc1
v4.6.0-rc2
v4.7.0-rc1
v4.8.0-rc1
v4.9.0-rc1
v5.*
v5.0.0-rc1
v5.1.0-rc1
v5.2.0-rc1
v5.2.0-rc2
v7.*
v7.8.0
v7.8.1
v7.8.10
v7.8.10-rc3
v7.8.10-rc4
v7.8.10-rc5
v7.8.11
v7.8.11-rc1
v7.8.12
v7.8.12-rc1
v7.8.12-rc2
v7.8.2
v7.8.3
v7.8.4
v7.8.5
v7.8.6
v7.8.7
v7.8.8
v7.8.9
v8.*
v8.1.0
v8.1.0-rc2
v8.1.1
v8.1.1-rc1
v8.1.1-rc2
v8.1.2
v8.1.2-rc1
v8.1.2-rc2
v8.1.3
v8.1.3-rc1
v8.1.3-rc2
v9.*
v9.0.0
v9.0.0-rc2
v9.0.1
v9.0.1-rc1
v9.1.0
v9.1.0-rc2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-43754.json"