« Volver al listado

CVE-2024-34029

Estado: AnalizadaMedia (4.3)—

Mattermost versions 9.5.x <= 9.5.3, 9.7.x <= 9.7.1 and 8.1.x <= 8.1.12 fail to perform a proper authorization check in the /api/v4/groups/<group-id>/channels/<channel-id>/link endpoint which allows a user to learn the members of an AD/LDAP group that is linked to a team by adding the group to a channel, even if the user has no access to the team.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-34029",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-34029",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-05-28T14:46:22.213261Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "responsibledisclosure@mattermost.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "responsibledisclosure@mattermost.com",
      "affectedData": [
        {
          "vendor": "Mattermost",
          "product": "Mattermost",
          "versions": [
            {
              "status": "affected",
              "version": "9.5.0",
              "versionType": "semver",
              "lessThanOrEqual": "9.5.3"
            },
            {
              "status": "affected",
              "version": "9.7.0",
              "versionType": "semver",
              "lessThanOrEqual": "9.7.1"
            },
            {
              "status": "affected",
              "version": "8.1.0",
              "versionType": "semver",
              "lessThanOrEqual": "8.1.12"
            },
            {
              "status": "unaffected",
              "version": "9.8.0"
            },
            {
              "status": "unaffected",
              "version": "9.5.4"
            },
            {
              "status": "unaffected",
              "version": "9.7.2"
            },
            {
              "status": "unaffected",
              "version": "8.1.13"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:mattermost:mattermost:-:*:*:*:*:*:*:*"
          ],
          "vendor": "mattermost",
          "product": "mattermost",
          "versions": [
            {
              "status": "affected",
              "version": "9.5.0",
              "versionType": "semver",
              "lessThanOrEqual": "9.5.3"
            },
            {
              "status": "affected",
              "version": "9.7.0",
              "versionType": "semver",
              "lessThanOrEqual": "9.7.1"
            },
            {
              "status": "affected",
              "version": "8.1.0",
              "versionType": "semver",
              "lessThanOrEqual": "8.1.12"
            },
            {
              "status": "unaffected",
              "version": "9.8.0"
            },
            {
              "status": "unaffected",
              "version": "9.5.4"
            },
            {
              "status": "unaffected",
              "version": "9.7.2"
            },
            {
              "status": "unaffected",
              "version": "8.1.13"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2024-05-26T14:15:09.367",
  "references": [
    {
      "url": "https://mattermost.com/security-updates",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "responsibledisclosure@mattermost.com"
    },
    {
      "url": "https://mattermost.com/security-updates",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "responsibledisclosure@mattermost.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Mattermost versions 9.5.x <= 9.5.3, 9.7.x <= 9.7.1 and 8.1.x <= 8.1.12 fail to perform a proper authorization check in the /api/v4/groups/<group-id>/channels/<channel-id>/link endpoint which allows a user to learn the members of an AD/LDAP group that is linked to a team by adding the group to a channel, even if the user has no access to the team."
    },
    {
      "lang": "es",
      "value": "Las versiones 9.5.x &lt;= 9.5.3, 9.7.x &lt;= 9.7.1 y 8.1.x &lt;= 8.1.12 de Mattermost no realizan una verificación de autorización adecuada en /api/v4/groups// canales//link endpoint que permite a un usuario conocer los miembros de un grupo AD/LDAP que está vinculado a un equipo agregando el grupo a un canal, incluso si el usuario no tiene acceso al equipo."
    }
  ],
  "lastModified": "2026-06-17T07:32:46.773",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "47448305-8E05-4AEE-9E7B-D52AC86C7370",
              "versionEndExcluding": "8.1.13",
              "versionStartIncluding": "8.1.0"
            },
            {
              "criteria": "cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "73F3450F-7A4F-450D-BC68-E726D347636F",
              "versionEndExcluding": "9.5.4",
              "versionStartIncluding": "9.5.0"
            },
            {
              "criteria": "cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "44A14BC6-9CCB-4D0B-9C07-79767507C4D2",
              "versionEndExcluding": "9.7.2",
              "versionStartIncluding": "9.7.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "responsibledisclosure@mattermost.com"
}