Description
Improper Access Control in Mattermost Server versions 8.1.x before 8.1.11 allows an attacker that is in a channel with an active call to keep participating in the call even if they are removed from the channel
No analysis available yet.
Remediation
Vendor Solution
Update Mattermost Server to versions 9.5.0, 8.1.11 or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-1339 | Improper Access Control in Mattermost Server versions 8.1.x before 8.1.11 allows an attacker that is in a channel with an active call to keep participating in the call even if they are removed from the channel |
Github GHSA |
GHSA-xp9j-8p68-9q93 | Mattermost Server Improper Access Control |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
Tue, 04 Mar 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 13 Dec 2024 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost
Mattermost mattermost Server |
|
| Weaknesses | CWE-273 | |
| CPEs | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mattermost
Mattermost mattermost Server |
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2025-02-27T19:28:16.621Z
Reserved: 2024-04-03T10:03:48.279Z
Link: CVE-2024-21848
Updated: 2024-08-01T22:27:36.465Z
Status : Analyzed
Published: 2024-04-05T09:15:09.017
Modified: 2024-12-13T16:36:59.837
Link: CVE-2024-21848
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA