VYPR
Medium severity4.3NVD Advisory· Published Feb 29, 2024· Updated Jun 17, 2026

CVE-2024-23493

CVE-2024-23493

Description

Mattermost fails to properly authorize the requests fetching team associated AD/LDAP groups, allowing a user to fetch details of AD/LDAP groups of a team that they are not a member of.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/mattermost/mattermost/server/v8Go
>= 9.4.0, < 9.4.29.4.2
github.com/mattermost/mattermost/server/v8Go
>= 9.3.0, < 9.3.19.3.1
github.com/mattermost/mattermost/server/v8Go
>= 9.2.0, < 9.2.59.2.5

Affected products

29

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.