CyberRota Analysis
This is a low severity vulnerability with a CVSS score of 3.1. Exploitation may require the attacker to be authenticated.
CVE
CVE-2023-3584
Severity
LOW
CVSS
3.1
EPSS
0.35%
Original NVD Description
Mattermost fails to properly check the authorization of POST /api/v4/teams when passing a team override scheme ID in the request, allowing an authenticated attacker with knowledge of a Team Override Scheme ID to create a new team with said team override scheme.
Related CVEs
Other vulnerabilities affecting the same vendor(s)