CVE-2024-34029
26.05.2024, 14:15
Mattermost versions 9.5.x <= 9.5.3, 9.7.x <= 9.7.1 and 8.1.x <= 8.1.12 fail to perform a proper authorization check in the /api/v4/groups/<group-id>/channels/<channel-id>/link endpointwhich allows a userto learn the members ofan AD/LDAP group that is linked to a team by adding the group to a channel, even if the user has no access to the team.Enginsight
Vendor | Product | Version |
---|---|---|
mattermost | mattermost | 9.5.3 ≤ 𝑥 ≤ 9.5.3 |
mattermost | mattermost | 9.7.1 ≤ 𝑥 ≤ 9.7.1 |
mattermost | mattermost | 8.1.12 ≤ 𝑥 ≤ 8.1.12 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration