CVE-2024-40884: Unauthorized disabling of invite URL
Published Aug 22, 2024
·Updated
Mattermost versions 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 fail to properly enforce permissions which allows a team admin user without "Add Team Members" permission to disable the invite URL.
Affected Software
4 affected componentsFixes available
go/github.com/mattermost/mattermost/server/v8>=9.10.0<9.10.1
9.10.1
go/github.com/mattermost/mattermost/server/v8>=9.5.0<9.5.8
9.5.8
Mattermost Mattermost Server>=9.5.0<9.5.8
Mattermost Mattermost Server=9.10.0
Remediation
Information
Update Mattermost to versions 9.11.0, 9.5.8, 9.10.1 or higher.
Event History
Aug 22, 2024
CVE Published
via MITRE·03:17 PM
Data Sourced
via MITRE·03:17 PM
RemedyDescriptionSeverityWeakness
Advisory Published
via GitHub·06:31 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-40884?
CVE-2024-40884 has a moderate severity rating due to its potential impact on access control.
2
How do I fix CVE-2024-40884?
To fix CVE-2024-40884, upgrade to Mattermost version 9.10.1 or 9.5.8.
3
What versions of Mattermost are affected by CVE-2024-40884?
Mattermost versions 9.5.x up to 9.5.7 and 9.10.x up to 9.10.0 are affected by CVE-2024-40884.
4
What is the primary issue caused by CVE-2024-40884?
CVE-2024-40884 allows team admin users without the 'Add Team Members' permission to disable the invite URL.
5
Who is impacted by CVE-2024-40884?
Users with team admin privileges in affected Mattermost versions may be impacted by CVE-2024-40884.