VYPR
Moderate severityNVD Advisory· Published Feb 29, 2024· Updated Aug 1, 2024

Team associated AD/LDAP Groups Leaked due to missing authorization

CVE-2024-23493

Description

Mattermost fails to properly authorize the requests fetching team associated AD/LDAP groups, allowing a user to fetch details of AD/LDAP groups of a team that they are not a member of.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/mattermost/mattermost/server/v8Go
>= 9.4.0, < 9.4.29.4.2
github.com/mattermost/mattermost/server/v8Go
>= 9.3.0, < 9.3.19.3.1
github.com/mattermost/mattermost/server/v8Go
>= 9.2.0, < 9.2.59.2.5

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.