Users maintain access to active call after being removed from a channel
Vulnerability Description
Improper Access Control in Mattermost Server versions 8.1.x before 8.1.11 allows an attacker that is in a channel with an active call to keep participating in the call even if they are removed from the channel
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-21848
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Leandro Chaves (brdoors3)
References
More from Mattermost
View All →Affected Vendor
Mattermost
View all reports →