Description
Mattermost fails to update the permissions of the current session for a user who was just demoted to guest, allowing freshly demoted guests to change group names.
No analysis available yet.
Remediation
Vendor Solution
Update Mattermost Server to versions 8.1.7, 9.3.0 or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0319 | Mattermost fails to update the permissions of the current session for a user who was just demoted to guest, allowing freshly demoted guests to change group names. |
Github GHSA |
GHSA-9w97-9rqx-8v4j | Mattermost allows demoted guests to change group names |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
Tue, 17 Jun 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2025-06-17T13:35:30.706Z
Reserved: 2023-12-21T08:00:43.432Z
Link: CVE-2023-50333
Updated: 2024-08-02T22:16:46.618Z
Status : Modified
Published: 2024-01-02T10:15:08.723
Modified: 2024-11-21T08:36:51.637
Link: CVE-2023-50333
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA