Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-4198

Опубликовано: 26 апр. 2024
Источник: redhat
CVSS3: 2.7

Описание

Mattermost versions 9.6.0, 9.5.x before 9.5.3, and 8.1.x before 8.1.12 fail to fully validate role changes which allows an attacker authenticated as team admin to demote users to guest via crafted HTTP requests.

A flaw was found in Mattermost, where it failed to fully validate role changes. This flaw allows an attacker authenticated as team admin to demote users to guests via crafted HTTP requests.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/acm-grafana-rhel8Fix deferred
Red Hat Advanced Cluster Security 3advanced-cluster-security/rhacs-docs-rhel8Fix deferred
Red Hat Advanced Cluster Security 3advanced-cluster-security/rhacs-main-rhel8Fix deferred
Red Hat Advanced Cluster Security 3advanced-cluster-security/rhacs-rhel8-operatorFix deferred
Red Hat Advanced Cluster Security 3advanced-cluster-security/rhacs-roxctl-rhel8Fix deferred
Red Hat Advanced Cluster Security 3advanced-cluster-security/rhacs-scanner-db-rhel8Fix deferred
Red Hat Advanced Cluster Security 3advanced-cluster-security/rhacs-scanner-rhel8Fix deferred
Red Hat OpenShift Container Platform 4openshift4/ose-grafanaNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-284
https://bugzilla.redhat.com/show_bug.cgi?id=2277334mattermost: fail to fully validate role changes which allows an attacker authenticated as team admin to demote users to guest

2.7 Low

CVSS3

Связанные уязвимости

CVSS3: 2.7
nvd
больше 2 лет назад

Mattermost versions 9.6.0, 9.5.x before 9.5.3, and 8.1.x before 8.1.12 fail to fully validate role changes which allows an attacker authenticated as team admin to demote users to guest via crafted HTTP requests.

CVSS3: 2.7
debian
больше 2 лет назад

Mattermost versions 9.6.0, 9.5.x before 9.5.3, and 8.1.x before 8.1.12 ...

CVSS3: 2.7
github
больше 2 лет назад

Mattermost fails to fully validate role changes

2.7 Low

CVSS3

Уязвимость CVE-2024-4198