CVE-2024-1888: Existing server guests invited to the team by members without "invite_guest" permission
Mattermost fails to check the "inviteguest" permission when inviting guests of other teams to a team, allowing a member with permissions to add other members but not to add guests to add a guest to a team as long as the guest was already a guest in another team of the server
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1888?
CVE-2024-1888 is considered a medium severity vulnerability due to improper permission checks.
How do I fix CVE-2024-1888?
To fix CVE-2024-1888, upgrade to Mattermost version 8.1.9 or any version from 9.2.5 onwards.
What versions of Mattermost are affected by CVE-2024-1888?
CVE-2024-1888 affects Mattermost versions prior to 8.1.9 and versions between 9.2.0 to 9.2.5, 9.3.0 to 9.3.1, and 9.4.0 to 9.4.2.
What impact does CVE-2024-1888 have on Mattermost users?
CVE-2024-1888 allows unauthorized team guests to be invited by members who should not have the permission to do so.
Is CVE-2024-1888 exploitable in all Mattermost deployments?
CVE-2024-1888 is exploitable in any Mattermost deployment where user permissions are not correctly enforced.