Description
Mattermost fails to properly authorize the requests fetching team associated AD/LDAP groups, allowing a user to fetch details of AD/LDAP groups of a team that they are not a member of.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Update Mattermost Server to versions 9.5.0, 9.4.2, 9.3.1, 9.2.5, 8.1.9 or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0563 | Mattermost fails to properly authorize the requests fetching team associated AD/LDAP groups, allowing a user to fetch details of AD/LDAP groups of a team that they are not a member of. |
Github GHSA |
GHSA-7v3v-984v-h74r | Mattermost leaks details of AD/LDAP groups of a teams |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
Fri, 10 Jan 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost
Mattermost mattermost Server |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* cpe:2.3:a:mattermost:mattermost_server:9.3.0:-:*:*:*:*:*:* cpe:2.3:a:mattermost:mattermost_server:9.3.0:rc1:*:*:*:*:*:* cpe:2.3:a:mattermost:mattermost_server:9.3.0:rc2:*:*:*:*:*:* |
|
| Vendors & Products |
Mattermost
Mattermost mattermost Server |
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-08-01T23:06:24.717Z
Reserved: 2024-02-26T08:14:42.964Z
Link: CVE-2024-23493
Updated: 2024-08-01T23:06:24.717Z
Status : Analyzed
Published: 2024-02-29T08:15:47.380
Modified: 2025-01-10T15:34:43.287
Link: CVE-2024-23493
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA