VYPR
Moderate severityNVD Advisory· Published Feb 29, 2024· Updated Aug 1, 2024

Existing server guests invited to the team by members without "invite_guest" permission

CVE-2024-1888

Description

Mattermost fails to check the "invite_guest" permission when inviting guests of other teams to a team, allowing a member with permissions to add other members but not to add guests to add a guest to a team as long as the guest was already a guest in another team of the server

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/mattermost/mattermost/server/v8Go
>= 9.4.0, < 9.4.29.4.2
github.com/mattermost/mattermost/server/v8Go
>= 9.3.0, < 9.3.19.3.1
github.com/mattermost/mattermost/server/v8Go
>= 9.2.0, < 9.2.59.2.5
github.com/mattermost/mattermost/server/v8Go
< 8.1.98.1.9

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.