CVE-2024-23493: Team associated AD/LDAP Groups Leaked due to missing authorization
Mattermost fails to properly authorize the requests fetching team associated AD/LDAP groups, allowing a user to fetch details of AD/LDAP groups of a team that they are not a member of.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23493?
CVE-2024-23493 has not been officially rated, but it allows unauthorized access to Team associated AD/LDAP group details which poses a significant security risk.
How do I fix CVE-2024-23493?
To fix CVE-2024-23493, upgrade your Mattermost server to version 9.2.5, 9.3.1, or 9.4.2.
Who is affected by CVE-2024-23493?
CVE-2024-23493 affects Mattermost server versions up to 8.1.9 and from version 9.0.0 to 9.2.5, as well as from 9.4.0 to 9.4.2.
What types of requests are vulnerable due to CVE-2024-23493?
CVE-2024-23493 allows unauthorized requests to fetch details of AD/LDAP groups associated with teams that a user does not belong to.
What is the primary risk associated with CVE-2024-23493?
The primary risk of CVE-2024-23493 is that it can lead to data exposure of sensitive group information, potentially compromising user privacy and security.