This site requires JavaScript to be enabled to function correctly, please enable it.
Summary:
CVE-2024-40884 mattermost: permission enforcing failure allows a team admin user without "Add Team Members" permission to disable the invite URL
Product:
[Other] Security Response
Reporter:
OSIDB Bzimport <bzimport>
Component:
vulnerability Assignee:
Product Security DevOps Team <prodsec-dev>
Status:
NEW
---
QA Contact:
Severity:
low
Docs Contact:
Priority:
low
Version:
unspecified CC:
amctagga, anjoseph, aoconnor, bniver, caswilli, flucifre, gmeno, gparvin, jprabhak, kaycoth, lbainbri, mbenjamin, mhackett, njean, owatkins, pahickey, rhaigner, sostapov, vereddy, wtam
Target Milestone:
--- Keywords:
Security
Target Release:
---
Hardware:
All
OS:
Linux
Whiteboard:
Fixed In Version:
Doc Type:
If docs needed, set a value
Doc Text:
Story Points:
---
Clone Of:
Environment:
Last Closed:
Type:
---
Regression:
---
Mount Type:
---
Documentation:
---
CRM:
Verified Versions:
Category:
---
oVirt Team:
---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team:
---
Target Upstream Version:
Embargoed: