CVE-2024-31859: Member promoted to channel admin via playbooks run linking to channel
Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to perform proper authorization checks which allows a member running a playbook in an existing channel to be promoted to a channel admin
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-31859?
CVE-2024-31859 has a medium severity rating due to improper authorization checks in Mattermost.
How do I fix CVE-2024-31859?
To fix CVE-2024-31859, upgrade Mattermost to the latest version that addresses the authorization vulnerabilities.
What versions of Mattermost are affected by CVE-2024-31859?
CVE-2024-31859 affects Mattermost versions 9.5.x up to 9.5.3, 9.6.x up to 9.6.1, and 8.1.x up to 8.1.12.
What type of vulnerability is CVE-2024-31859?
CVE-2024-31859 is an authorization bypass vulnerability that allows unauthorized promotion to channel admin.
Who can be impacted by CVE-2024-31859?
Members running a playbook in affected Mattermost channels can be impacted by being improperly promoted to channel admins.