Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-5263-pm2h-m7hw: Mattermost doesn't restrict which roles can promote a user as system admin

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to restrict which roles can promote a user as system admin which allows a System Role with edit access to the permissions section of system console to update their role (e.g. member) to include the manage_system permission, effectively becoming a System Admin.

ghsa
#git
  1. GitHub Advisory Database
  2. GitHub Reviewed
  3. CVE-2024-8071

Mattermost doesn’t restrict which roles can promote a user as system admin

Moderate severity GitHub Reviewed Published Aug 22, 2024 to the GitHub Advisory Database • Updated Aug 23, 2024

Package

gomod github.com/mattermost/mattermost/server/v8 (Go)

Affected versions

>= 9.9.0, < 9.9.2

>= 9.5.0, < 9.5.8

>= 9.10.0, < 9.10.1

>= 9.8.0, < 9.8.3

Patched versions

9.9.2

9.5.8

9.10.1

9.8.3

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to restrict which roles can promote a user as system admin which allows a System Role with edit access to the permissions section of system console to update their role (e.g. member) to include the manage_system permission, effectively becoming a System Admin.

References

  • https://nvd.nist.gov/vuln/detail/CVE-2024-8071
  • https://mattermost.com/security-updates

Published to the GitHub Advisory Database

Aug 22, 2024

Last updated

Aug 23, 2024

ghsa: Latest News

GHSA-486g-47cc-8wxf: aiocpa contains credential harvesting code