CVE Vulnerabilities

CVE-2024-8071

Published: Aug 22, 2024 | Modified: Aug 23, 2024
CVSS 3.x
7.2
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to restrict which roles can promote a user as system admin which allows a System Role with edit access to the permissions section of system console to update their role (e.g. member) to include the manage_system permission, effectively becoming a System Admin.

Affected Software

Name Vendor Start Version End Version
Mattermost Mattermost 9.5.0 (including) 9.5.8 (excluding)
Mattermost Mattermost 9.8.0 (including) 9.8.3 (excluding)
Mattermost Mattermost 9.9.0 (including) 9.9.2 (excluding)
Mattermost Mattermost 9.10.0 (including) 9.10.1 (excluding)

References