CVE-2024-8071
System Role with edit access to permissions can elevate themselves to system admin
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to restrict which roles can promote a user as system admin which allows a System Role with edit access to the permissions section of system console to update their role (e.g. member) to include the `manage_system` permission, effectively becoming a System Admin.
Las versiones de Mattermost 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 y 9.8.x <= 9.8.2 no restringen qué roles pueden promover a un usuario como administrador del sistema y cuáles permite que una función del sistema con acceso de edición a la sección de permisos de la consola del sistema actualice su función (por ejemplo, miembro) para incluir el permiso `manage_system`, convirtiéndose efectivamente en un administrador del sistema.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2024-08-22 CVE Reserved
- 2024-08-22 CVE Published
- 2024-08-22 CVE Updated
- 2024-08-24 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-284: Improper Access Control
CAPEC
References (1)
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mattermost Search vendor "Mattermost" | Mattermost Search vendor "Mattermost" for product "Mattermost" | >= 9.9.0 <= 9.9.1 Search vendor "Mattermost" for product "Mattermost" and version " >= 9.9.0 <= 9.9.1" | en |
Affected
| ||||||
Mattermost Search vendor "Mattermost" | Mattermost Search vendor "Mattermost" for product "Mattermost" | >= 9.5.0 <= 9.5.7 Search vendor "Mattermost" for product "Mattermost" and version " >= 9.5.0 <= 9.5.7" | en |
Affected
| ||||||
Mattermost Search vendor "Mattermost" | Mattermost Search vendor "Mattermost" for product "Mattermost" | 9.10.0 Search vendor "Mattermost" for product "Mattermost" and version "9.10.0" | en |
Affected
| ||||||
Mattermost Search vendor "Mattermost" | Mattermost Search vendor "Mattermost" for product "Mattermost" | >= 9.8.0 <= 9.8.2 Search vendor "Mattermost" for product "Mattermost" and version " >= 9.8.0 <= 9.8.2" | en |
Affected
|