Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-4198

Опубликовано: 26 апр. 2024
Источник: redhat
CVSS3: 2.7
EPSS Низкий

Описание

Mattermost versions 9.6.0, 9.5.x before 9.5.3, and 8.1.x before 8.1.12 fail to fully validate role changes which allows an attacker authenticated as team admin to demote users to guest via crafted HTTP requests.

A flaw was found in Mattermost, where it failed to fully validate role changes. This flaw allows an attacker authenticated as team admin to demote users to guests via crafted HTTP requests.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/acm-grafana-rhel8Fix deferred
Red Hat Advanced Cluster Security 3advanced-cluster-security/rhacs-docs-rhel8Fix deferred
Red Hat Advanced Cluster Security 3advanced-cluster-security/rhacs-main-rhel8Fix deferred
Red Hat Advanced Cluster Security 3advanced-cluster-security/rhacs-rhel8-operatorFix deferred
Red Hat Advanced Cluster Security 3advanced-cluster-security/rhacs-roxctl-rhel8Fix deferred
Red Hat Advanced Cluster Security 3advanced-cluster-security/rhacs-scanner-db-rhel8Fix deferred
Red Hat Advanced Cluster Security 3advanced-cluster-security/rhacs-scanner-rhel8Fix deferred
Red Hat OpenShift Container Platform 4openshift4/ose-grafanaNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-284
https://bugzilla.redhat.com/show_bug.cgi?id=2277334mattermost: fail to fully validate role changes which allows an attacker authenticated as team admin to demote users to guest

EPSS

Процентиль: 34%
0.00138
Низкий

2.7 Low

CVSS3

Связанные уязвимости

CVSS3: 2.7
nvd
почти 2 года назад

Mattermost versions 9.6.0, 9.5.x before 9.5.3, and 8.1.x before 8.1.12 fail to fully validate role changes which allows an attacker authenticated as team admin to demote users to guest via crafted HTTP requests.

CVSS3: 2.7
debian
почти 2 года назад

Mattermost versions 9.6.0, 9.5.x before 9.5.3, and 8.1.x before 8.1.12 ...

CVSS3: 2.7
github
почти 2 года назад

Mattermost fails to fully validate role changes

EPSS

Процентиль: 34%
0.00138
Низкий

2.7 Low

CVSS3