Логотип exploitDog
bind:CVE-2024-29221
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-29221

Количество 3

Количество 3

nvd логотип

CVE-2024-29221

почти 2 года назад

Improper Access Control in Mattermost Server versions 9.5.x before 9.5.2, 9.4.x before 9.4.4, 9.3.x before 9.3.3, 8.1.x before 8.1.11 lacked proper access control in the `/api/v4/users/me/teams` endpoint allowing a team admin to get the invite ID of their team, thus allowing them to invite users, even if the "Add Members" permission was explicitly removed from team admins.

CVSS3: 4.7
EPSS: Низкий
debian логотип

CVE-2024-29221

почти 2 года назад

Improper Access Control in Mattermost Server versions 9.5.x before 9.5 ...

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-w67v-ph4x-f48q

почти 2 года назад

Mattermost Server Improper Access Control

CVSS3: 4.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-29221

Improper Access Control in Mattermost Server versions 9.5.x before 9.5.2, 9.4.x before 9.4.4, 9.3.x before 9.3.3, 8.1.x before 8.1.11 lacked proper access control in the `/api/v4/users/me/teams` endpoint allowing a team admin to get the invite ID of their team, thus allowing them to invite users, even if the "Add Members" permission was explicitly removed from team admins.

CVSS3: 4.7
0%
Низкий
почти 2 года назад
debian логотип
CVE-2024-29221

Improper Access Control in Mattermost Server versions 9.5.x before 9.5 ...

CVSS3: 4.7
0%
Низкий
почти 2 года назад
github логотип
GHSA-w67v-ph4x-f48q

Mattermost Server Improper Access Control

CVSS3: 4.7
0%
Низкий
почти 2 года назад

Уязвимостей на страницу