CVE-2024-40884Improper Access Control in Mattermost Mattermost-server

Severity
2.7LOWNVD
EPSS
0.1%
top 72.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 22
Latest updateAug 30

Description

Mattermost versions 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 fail to properly enforce permissions which allows a team admin user without "Add Team Members" permission to disable the invite URL.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:LExploitability: 1.2 | Impact: 1.4

Affected Packages4 packages

NVDmattermost/mattermost_server9.5.09.5.8+1
Gogithub.com/mattermost_mattermost-server9.5.0+incompatible9.5.8+incompatible+1
CVEListV5mattermost/mattermost9.5.09.5.7+1

🔴Vulnerability Details

4
OSV
Mattermost allows team admin user without "Add Team Members" permission to disable invite URL in github.com/mattermost/mattermost-server2024-08-30
OSV
Mattermost allows team admin user without "Add Team Members" permission to disable invite URL2024-08-22
CVEList
Unauthorized disabling of invite URL2024-08-22
GHSA
Mattermost allows team admin user without "Add Team Members" permission to disable invite URL2024-08-22

📋Vendor Advisories

1
Red Hat
mattermost: permission enforcing failure allows a team admin user without "Add Team Members" permission to disable the invite URL2024-08-22
CVE-2024-40884 — Improper Access Control | cvebase