Mattermost versions 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 fail to properly enforce permissions which allows a team admin user without "Add Team Members" permission to disable the invite URL.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-2478 Mattermost versions 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 fail to properly enforce permissions which allows a team admin user without "Add Team Members" permission to disable the invite URL.
Github GHSA Github GHSA GHSA-3j95-8g47-fpwh Mattermost allows team admin user without "Add Team Members" permission to disable invite URL
Fixes

Solution

Update Mattermost to versions 9.11.0, 9.5.8, 9.10.1 or higher.


Workaround

No workaround given by the vendor.

History

Thu, 17 Oct 2024 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost
Mattermost mattermost Server
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
cpe:2.3:a:mattermost:mattermost_server:9.10.0:*:*:*:*:*:*:*
Vendors & Products Mattermost
Mattermost mattermost Server

Fri, 23 Aug 2024 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 22 Aug 2024 23:30:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Low


Thu, 22 Aug 2024 15:30:00 +0000

Type Values Removed Values Added
Description Mattermost versions 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 fail to properly enforce permissions which allows a team admin user without "Add Team Members" permission to disable the invite URL.
Title Unauthorized disabling of invite URL
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2024-08-22T18:08:37.730Z

Reserved: 2024-08-16T17:27:00.338Z

Link: CVE-2024-40884

cve-icon Vulnrichment

Updated: 2024-08-22T18:08:33.413Z

cve-icon NVD

Status : Analyzed

Published: 2024-08-22T16:15:08.797

Modified: 2024-10-17T14:05:16.247

Link: CVE-2024-40884

cve-icon Redhat

Severity : Low

Publid Date: 2024-08-22T16:15:08Z

Links: CVE-2024-40884 - Bugzilla

cve-icon OpenCVE Enrichment

No data.