CVE-2024-21848: Users maintain access to active call after being removed from a channel
Published Apr 5, 2024
·Updated
Improper Access Control in Mattermost Server versions 8.1.x before 8.1.11 allows an attacker that is in a channel with an active call to keep participating in the call even if they are removed from the channel
Affected Software
2 affected componentsFixes available
go/github.com/mattermost/mattermost/server/v8<8.1.11
8.1.11
Mattermost Mattermost Server>=8.1.0<8.1.11
Remediation
Information
Update Mattermost Server to versions 9.5.0, 8.1.11 or higher.
Event History
Apr 5, 2024
CVE Published
via MITRE·08:13 AM
Data Sourced
via MITRE·08:13 AM
RemedyDescriptionSeverityWeakness
Advisory Published
via GitHub·09:30 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-21848?
CVE-2024-21848 has a moderate severity due to the improper access control affecting active call participation.
2
How do I fix CVE-2024-21848?
To fix CVE-2024-21848, upgrade Mattermost Server to version 8.1.11 or later.
3
What versions are affected by CVE-2024-21848?
CVE-2024-21848 affects Mattermost Server versions 8.1.0 to 8.1.10.
4
What is the impact of CVE-2024-21848?
The impact of CVE-2024-21848 allows an attacker to remain in an active call after being removed from the channel.
5
Is there a workaround for CVE-2024-21848?
No specific workaround is recommended; updating to the latest version is the best solution.