First published: Fri Apr 05 2024(Updated: )
Improper Access Control in Mattermost Server versions 9.5.x before 9.5.2, 9.4.x before 9.4.4, 9.3.x before 9.3.3, 8.1.x before 8.1.11 lacked proper access control in the `/api/v4/users/me/teams` endpoint allowing a team admin to get the invite ID of their team, thus allowing them to invite users, even if the "Add Members" permission was explicitly removed from team admins.
Credit: responsibledisclosure@mattermost.com responsibledisclosure@mattermost.com
Affected Software | Affected Version | How to fix |
---|---|---|
go/github.com/mattermost/mattermost/server/v8 | >=9.3.0<9.3.3 | 9.3.3 |
go/github.com/mattermost/mattermost/server/v8 | >=9.4.0<9.4.4 | 9.4.4 |
go/github.com/mattermost/mattermost/server/v8 | >=9.5.0<9.5.2 | 9.5.2 |
go/github.com/mattermost/mattermost/server/v8 | >=8.1.0<8.1.11 | 8.1.11 |
Mattermost Mattermost Server | >=8.1.0<8.1.11 | |
Mattermost Mattermost Server | >=9.3.0<9.3.3 | |
Mattermost Mattermost Server | >=9.4.0<9.4.4 | |
Mattermost Mattermost Server | >=9.5.0<9.5.2 | |
>=8.1.0<8.1.11 | ||
>=9.3.0<9.3.3 | ||
>=9.4.0<9.4.4 | ||
>=9.5.0<9.5.2 |
Update Mattermost Server to versions 9.6.0, 9.5.2, 9.4.4, 9.3.3, 8.1.11 or higher.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.