Description
Mattermost fails to check the required permissions in the POST /api/v4/channels/stats/member_count API resulting in channel member counts being leaked to a user without permissions.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Update Mattermost Server to versions 8.1.8, 9.4.0 or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0710 | Mattermost fails to check the required permissions in the POST /api/v4/channels/stats/member_count API resulting in channel member counts being leaked to a user without permissions. |
Github GHSA |
GHSA-r833-w756-h5p2 | Mattermost fails to check the required permissions |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
No history.
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-08-01T23:28:12.437Z
Reserved: 2024-01-30T10:23:06.717Z
Link: CVE-2024-24776
Updated: 2024-08-01T23:28:12.437Z
Status : Modified
Published: 2024-02-09T15:15:08.547
Modified: 2024-11-21T08:59:40.850
Link: CVE-2024-24776
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA