Invite ID available to team admins even without the "Add Members" permission
Vulnerability Description
Improper Access Control in Mattermost Server versions 9.5.x before 9.5.2, 9.4.x before 9.4.4, 9.3.x before 9.3.3, 8.1.x before 8.1.11 lacked proper access control in the `/api/v4/users/me/teams` endpoint allowing a team admin to get the invite ID of their team, thus allowing them to invite users, even if the "Add Members" permission was explicitly removed from team admins.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-29221
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- omar ahmed (omar-ahmed)
References
More from Mattermost
View All →Affected Vendor
Mattermost
View all reports →