CVE-2024-21848

Improper Access Control in Mattermost Server versions 8.1.x before 8.1.11 allows an attacker that is in a channel with an active call to keep participating in the call even if they are removed from the channel
Configurations

No configuration.

History

21 Nov 2024, 08:55

Type Values Removed Values Added
References () https://mattermost.com/security-updates - () https://mattermost.com/security-updates -
Summary
  • (es) El control de acceso inadecuado en las versiones 8.1.x anteriores a 8.1.11 de Mattermost Server permite que un atacante que se encuentra en un canal con una llamada activa siga participando en la llamada incluso si se elimina del canal.

05 Apr 2024, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-05 09:15

Updated : 2024-11-21 08:55


NVD link : CVE-2024-21848

Mitre link : CVE-2024-21848

CVE.ORG link : CVE-2024-21848


JSON object : View

Products Affected

No product.

CWE
CWE-284

Improper Access Control