CVE-2023-47858
Status: ModifiedMedium (4.3)—
Mattermost fails to properly verify the permissions needed for viewing archived public channels, allowing a member of one team to get details about the archived public channels of another team via the GET /api/v4/teams/<team-id>/channels/deleted endpoint.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Base score: 4.3
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.36%
- Percentile among all scored CVEs: 28
- Score date: 10/7/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-284
- NVD-CWE-Other
References
Raw JSON (NVD)
Show
{
"id": "CVE-2023-47858",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2023-47858",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-02-06T16:29:43.414429Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "responsibledisclosure@mattermost.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 2.8
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "responsibledisclosure@mattermost.com",
"affectedData": [
{
"vendor": "Mattermost",
"product": "Mattermost",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "semver",
"lessThanOrEqual": "9.2.2"
},
{
"status": "affected",
"version": "0",
"versionType": "semver",
"lessThanOrEqual": "9.1.3"
},
{
"status": "affected",
"version": "0",
"versionType": "semver",
"lessThanOrEqual": "9.0.4"
},
{
"status": "affected",
"version": "0",
"versionType": "semver",
"lessThanOrEqual": "8.1.6"
},
{
"status": "unaffected",
"version": "8.1.7"
},
{
"status": "unaffected",
"version": "9.0.5"
},
{
"status": "unaffected",
"version": "9.1.4"
},
{
"status": "unaffected",
"version": "9.2.3"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2024-01-02T10:15:08.117",
"references": [
{
"url": "https://mattermost.com/security-updates",
"tags": [
"Vendor Advisory"
],
"source": "responsibledisclosure@mattermost.com"
},
{
"url": "https://mattermost.com/security-updates",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "responsibledisclosure@mattermost.com",
"description": [
{
"lang": "en",
"value": "CWE-284"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Mattermost fails to properly verify the permissions needed for viewing archived public channels, allowing a member of one team to get details about the archived public channels of another team via the GET /api/v4/teams/<team-id>/channels/deleted endpoint.\n\n"
},
{
"lang": "es",
"value": "Mattermost no verifica adecuadamente los permisos necesarios para ver los canales públicos archivados, lo que permite que un miembro de un equipo obtenga detalles sobre los canales públicos archivados de otro equipo a través de GET /api/v4/teams//channels/deleted endpoint."
}
],
"lastModified": "2026-06-17T06:33:25.600",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4FFBD373-195D-4481-B87D-5B329DBEC33D",
"versionEndExcluding": "8.1.7"
},
{
"criteria": "cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "707E5CDF-AD8D-4D91-8DE8-B32E6E06003B",
"versionEndExcluding": "9.0.5",
"versionStartIncluding": "9.0.0"
},
{
"criteria": "cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "689E6CCF-B722-4C95-AAB6-010CC285CF80",
"versionEndExcluding": "9.1.4",
"versionStartIncluding": "9.1.0"
},
{
"criteria": "cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "51A35D8A-9E04-4450-B27E-401B9D43CC12",
"versionEndExcluding": "9.2.3",
"versionStartIncluding": "9.2.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "responsibledisclosure@mattermost.com"
}