CVE-2024-40884 — Improper Access Control in Mattermost Mattermost-server
Severity
2.7LOWNVD
EPSS
0.1%
top 72.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 22
Latest updateAug 30
Description
Mattermost versions 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 fail to properly enforce permissions which allows a team admin user without "Add Team Members" permission to disable the invite URL.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:LExploitability: 1.2 | Impact: 1.4
Affected Packages4 packages
🔴Vulnerability Details
4OSV▶
Mattermost allows team admin user without "Add Team Members" permission to disable invite URL in github.com/mattermost/mattermost-server↗2024-08-30
OSV▶
Mattermost allows team admin user without "Add Team Members" permission to disable invite URL↗2024-08-22
GHSA▶
Mattermost allows team admin user without "Add Team Members" permission to disable invite URL↗2024-08-22
📋Vendor Advisories
1Red Hat▶
mattermost: permission enforcing failure allows a team admin user without "Add Team Members" permission to disable the invite URL↗2024-08-22