CVE-2024-40884
published 2024-08-22CVE-2024-40884: Mattermost versions 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 fail to properly enforce permissions which allows a team admin user without "Add Team Members" permission…
PriorityP49low2.7CVSS 3.1
AVNACLPRHUINSUCNINAL
EPSS
0.39%
31.7th percentile
Mattermost versions 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 fail to properly enforce permissions which allows a team admin user without "Add Team Members" permission to disable the invite URL.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | mattermost_mattermost-server | >= 9.10.0+incompatible < 9.10.1+incompatible | 9.10.1+incompatible |
| github.com | mattermost_mattermost-server | >= 9.5.0+incompatible < 9.5.8+incompatible | 9.5.8+incompatible |
| github.com | mattermost_mattermost_server_v8 | >= 9.10.0 < 9.10.1 | 9.10.1 |
| github.com | mattermost_mattermost_server_v8 | >= 9.5.0 < 9.5.8 | 9.5.8 |
| mattermost | mattermost | — | — |
| mattermost | mattermost | 9.5.0 – 9.5.7 | — |
| mattermost | mattermost_server | — | — |
| mattermost | mattermost_server | >= 9.5.0 < 9.5.8 | 9.5.8 |
CVSS provenance
nvdv3.12.7LOWCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L
vendor_redhat2.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Mattermost allows team admin user without "Add Team Members" permission to disable invite URL in github.com/mattermost/mattermost-server
osv·2024-08-30
CVE-2024-40884 Mattermost allows team admin user without "Add Team Members" permission to disable invite URL in github.com/mattermost/mattermost-server
Mattermost allows team admin user without "Add Team Members" permission to disable invite URL in github.com/mattermost/mattermost-server
Mattermost allows team admin user without "Add Team Members" permission to disable invite URL in github.com/mattermost/mattermost-server
OSV
Mattermost allows team admin user without "Add Team Members" permission to disable invite URL
osv·2024-08-22
CVE-2024-40884 [MEDIUM] Mattermost allows team admin user without "Add Team Members" permission to disable invite URL
Mattermost allows team admin user without "Add Team Members" permission to disable invite URL
Mattermost versions 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 fail to properly enforce permissions which allows a team admin user without "Add Team Members" permission to disable the invite URL.
GHSA
Mattermost allows team admin user without "Add Team Members" permission to disable invite URL
ghsa·2024-08-22
CVE-2024-40884 [MEDIUM] CWE-284 Mattermost allows team admin user without "Add Team Members" permission to disable invite URL
Mattermost allows team admin user without "Add Team Members" permission to disable invite URL
Mattermost versions 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 fail to properly enforce permissions which allows a team admin user without "Add Team Members" permission to disable the invite URL.
Red Hat
mattermost: permission enforcing failure allows a team admin user without "Add Team Members" permission to disable the invite URL
vendor_redhat·2024-08-22·CVSS 2.7
CVE-2024-40884 [LOW] CWE-284 mattermost: permission enforcing failure allows a team admin user without "Add Team Members" permission to disable the invite URL
mattermost: permission enforcing failure allows a team admin user without "Add Team Members" permission to disable the invite URL
Mattermost versions 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 fail to properly enforce permissions which allows a team admin user without "Add Team Members" permission to disable the invite URL.
Package: rhacm2/acm-grafana-rhel8 (Red Hat Advanced Cluster Management for Kubernetes 2) - Fix deferred
Package: advanced-cluster-security/rhacs-central-db-rhel8 (Red Hat Advanced Cluster Security 4) - Fix deferred
Package: advanced-cluster-security/rhacs-main-rhel8 (Red Hat Advanced Cluster Security 4) - Fix deferred
Package: advanced-cluster-security/rhacs-rhel8-operator (Red Hat Advanced Cluster Security 4) - Fix deferred
Package: advanced-cluster-security/rhacs-roxctl-r
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-08-22
Published