Launch Week Day 1: Announcing Security Design Review
MEDIUM 4.7 Go

Mattermost doesn't restrict which roles can promote a user as system admin

GHSA-5263-pm2h-m7hw · CVE-2024-8071 · GO-2024-3094

Published · Modified

Description

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to restrict which roles can promote a user as system admin which allows a System Role with edit access to the permissions section of system console to update their role (e.g. member) to include the manage_system permission, effectively becoming a System Admin.

Ready to move

Start Securing

Free, no credit card | First findings in minutes