PT-2024-22815 · Mattermost · Mattermost

Juho Nurminen

·

Published

2024-05-26

·

Updated

2024-06-14

·

CVE-2024-29215

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Mattermost versions 8.1.x through 8.1.12 Mattermost versions 9.5.x through 9.5.3 Mattermost versions 9.6.x through 9.6.1 Mattermost versions 9.7.x through 9.7.1
Description The issue is related to a failure in enforcing proper access control, allowing a user to run a slash command in a channel they are not a member of. This can be achieved by linking a playbook run to that channel and running a slash command as a playbook task command.
Recommendations For versions 8.1.x through 8.1.12, consider restricting access to the playbook run feature to prevent exploitation. For versions 9.5.x through 9.5.3, restrict access to the slash command feature in channels where the user is not a member. For versions 9.6.x through 9.6.1, avoid using the playbook task command to run slash commands in channels where the user is not a member. For versions 9.7.x through 9.7.1, consider disabling the linking of playbook runs to channels where the user is not a member as a temporary workaround.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-29215

Affected Products

Mattermost