← Back

CVE-2023-2788

nvd nist
Published: Jun 16, 2023Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Exploitability: 1.2 / Impact: 5.2
Source: NVD

Description

Mattermost fails to check if an admin user account active after an oauth2 flow is started, allowing an attacker with admin privileges to retain persistent access to Mattermost by obtaining an oauth2 access token while the attacker's account is deactivated.

Affected (4)

1 product
Mattermost
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Mattermost
From 7.1.0 to 7.1.9
From 7.8.0 to 7.8.4
From 7.9.0 to 7.9.3
Version 7.10.0

References (2)

Source: responsibledisclosure@mattermost.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.