CVE-2024-21848
Severity CVSS v4.0:
Pending analysis
Type:
CWE-284
Improper Access Control
Publication date:
05/04/2024
Last modified:
13/12/2024
Description
Improper Access Control in Mattermost Server versions 8.1.x before 8.1.11 allows an attacker that is in a channel with an active call to keep participating in the call even if they are removed from the channel<br />
<br />
Impact
Base Score 3.x
3.10
Severity 3.x
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* | 8.1.0 (including) | 8.1.11 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



