Description
Mattermost fails to check the "invite_guest" permission when inviting guests of other teams to a team, allowing a member with permissions to add other members but not to add guests to add a guest to a team as long as the guest was already a guest in another team of the server
No analysis available yet.
Remediation
Vendor Solution
Update Mattermost Server to versions 9.5.0, 9.4.2, 9.3.1, 9.2.5, 8.1.9 or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0685 | Mattermost fails to check the "invite_guest" permission when inviting guests of other teams to a team, allowing a member with permissions to add other members but not to add guests to add a guest to a team as long as the guest was already a guest in another team of the server |
Github GHSA |
GHSA-pfw6-5rx3-xh3c | Mattermost fails to check the "invite_guest" permission |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
Mon, 12 May 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost
Mattermost mattermost Server |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mattermost
Mattermost mattermost Server |
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-08-01T18:56:22.307Z
Reserved: 2024-02-26T09:37:53.013Z
Link: CVE-2024-1888
Updated: 2024-08-01T18:56:22.307Z
Status : Analyzed
Published: 2024-02-29T09:15:06.563
Modified: 2025-05-12T13:35:39.400
Link: CVE-2024-1888
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA