CVE-2024-4195: Low severity Mattermost Mattermost Server vulnerability
Mattermost versions 9.6.0, 9.5.x before 9.5.3, and 8.1.x before 8.1.12 fail to fully validate role changes, which allows an attacker authenticated as a team admin to promote guests to team admins via crafted HTTP requests.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
go/github.com/mattermost/mattermost-serverto a version that resolves this vulnerability.Fixed in 8.1.12 - Upgrade
Upgrade
go/github.com/mattermost/mattermost-serverto a version that resolves this vulnerability.Fixed in 9.5.3 - Upgrade
Upgrade
mattermost/mattermost-serverto a version that resolves this vulnerability.Fixed in 9.7.0 - Upgrade
Upgrade
mattermost/mattermost-serverto a version that resolves this vulnerability.Fixed in 9.6.1 - Upgrade
Upgrade
mattermost/mattermost-serverto a version that resolves this vulnerability.Fixed in 9.5.3 - Upgrade
Upgrade
mattermost/mattermost-serverto a version that resolves this vulnerability.Fixed in 8.1.12
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4195?
CVE-2024-4195 is considered a critical vulnerability due to its potential to allow unauthorized privilege escalation.
How do I fix CVE-2024-4195?
To fix CVE-2024-4195, upgrade Mattermost to version 8.1.12 or 9.5.3.
Who is affected by CVE-2024-4195?
CVE-2024-4195 affects Mattermost versions 9.6.0, 9.5.x before 9.5.3, and 8.1.x before 8.1.12.
What types of accounts can be misused in CVE-2024-4195?
CVE-2024-4195 allows authenticated team admins to promote guest accounts to team admins.
What does CVE-2024-4195 exploit?
CVE-2024-4195 exploits insufficient validation of role changes in Mattermost.