CVE-2024-4198: Low severity Mattermost Mattermost Server vulnerability
Mattermost versions 9.6.0, 9.5.x before 9.5.3, and 8.1.x before 8.1.12 fail to fully validate role changes which allows an attacker authenticated as team admin to demote users to guest via crafted HTTP requests.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
go/github.com/mattermost/mattermost-serverto a version that resolves this vulnerability.Fixed in 8.1.12 - Upgrade
Upgrade
go/github.com/mattermost/mattermost-serverto a version that resolves this vulnerability.Fixed in 9.5.3 - Upgrade
Upgrade
go/github.com/mattermost/mattermost-serverto a version that resolves this vulnerability.Fixed in 9.6.1 - Upgrade
Upgrade
Mattermost Serverto a version that resolves this vulnerability.Fixed in 9.7.0 - Upgrade
Upgrade
Mattermost Serverto a version that resolves this vulnerability.Fixed in 9.6.1 - Upgrade
Upgrade
Mattermost Serverto a version that resolves this vulnerability.Fixed in 9.5.3 - Upgrade
Upgrade
Mattermost Serverto a version that resolves this vulnerability.Fixed in 8.1.12
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4198?
CVE-2024-4198 has been rated with a medium severity level due to its implications on user roles and permissions.
How do I fix CVE-2024-4198?
To remediate CVE-2024-4198, upgrade to Mattermost version 9.5.3 or 8.1.12.
Who is affected by CVE-2024-4198?
Mattermost versions 9.6.0, 9.5.x before 9.5.3, and 8.1.x before 8.1.12 are affected by CVE-2024-4198.
What type of attack is described in CVE-2024-4198?
CVE-2024-4198 allows an authenticated attacker with team admin privileges to demote users to guest roles via crafted HTTP requests.
What versions have fixed the CVE-2024-4198 vulnerability?
Mattermost versions 9.5.3, 9.6.1, and 8.1.12 contain fixes for the CVE-2024-4198 vulnerability.