CVE-2023-43754

MEDIUM

Mattermost < 7.8.12 and 9.1.0-9.1.1 - Unauthorized Exposure of Archived Channel Permalink Previews

Title source: llm
STIX 2.1

Description

Mattermost fails to check whether the  “Allow users to view archived channels”  setting is enabled during permalink previews display, allowing members to view permalink previews of archived channels even if the “Allow users to view archived channels” setting is disabled. 

References (1)

Core 1
Core References

Scores

CVSS v3 4.3
EPSS 0.0035
EPSS Percentile 57.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-200
Status published
Products (4)
mattermost/mattermost 9.1.0
mattermost/mattermost < 7.8.12
mattermost/mattermost 9.1.0 - 9.1.1Go
mattermost/mattermost-server 0 - 7.8.13Go
Published Nov 27, 2023
Tracked Since Feb 18, 2026