CVE-2024-4198

Severity CVSS v4.0:
Pending analysis
Type:
CWE-284 Improper Access Control
Publication date:
26/04/2024
Last modified:
12/05/2025

Description

Mattermost versions 9.6.0, 9.5.x before 9.5.3, and 8.1.x before 8.1.12 fail to fully validate role changes which allows an attacker authenticated as team admin to demote users to guest via crafted HTTP requests.<br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* 8.1.0 (including) 8.1.12 (excluding)
cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* 9.5.0 (including) 9.5.3 (excluding)
cpe:2.3:a:mattermost:mattermost_server:9.6.0:-:*:*:*:*:*:*
cpe:2.3:a:mattermost:mattermost_server:9.6.0:rc1:*:*:*:*:*:*
cpe:2.3:a:mattermost:mattermost_server:9.6.0:rc2:*:*:*:*:*:*
cpe:2.3:a:mattermost:mattermost_server:9.6.0:rc3:*:*:*:*:*:*