PT-2024-2072 · Mattermost · Mattermost

Vultza

·

Published

2024-02-29

·

Updated

2025-01-11

·

CVE-2024-23493

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Mattermost versions prior to v8.1.9
Description The issue is related to a lack of proper authorization in requests fetching team-associated AD/LDAP groups, allowing a user to fetch details of AD/LDAP groups of a team they are not a member of. This can be exploited by a remote attacker to gain unauthorized access to user information. The vulnerable endpoint is related to the /plugins/playbooks/api/v0/telemetry/run/ component.
Recommendations For Mattermost versions prior to v8.1.9, update to version v8.1.9 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable /plugins/playbooks/api/v0/telemetry/run/ endpoint until a patch is available. Avoid using this endpoint to fetch team-associated AD/LDAP groups until the issue is resolved.

Fix

Missing Authorization

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2024-01966
BIT-MATTERMOST-2024-23493
CVE-2024-23493
GHSA-7V3V-984V-H74R
GO-2024-2590

Affected Products

Mattermost