CVE-2024-1888
Dashboard / Vulnerabilities / CVE-2024-1888
CVE-2024-1888
Published: 29 Feb 2024Last Modified: 25 Sept 2026
Aliases:
Summary: Existing server guests invited to the team by members without "invite_guest" permission
Details: Mattermost fails to check the "invite_guest" permission when inviting guests of other teams to a team, allowing a member with permissions to add other members but not to add guests to add a guest to a team as long as the guest was already a guest in another team of the server
References: https://mattermost.com/security-updates, https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/1xxx/CVE-2024-1888.json, https://nvd.nist.gov/vuln/detail/CVE-2024-1888
Affected packages
Package
Name:
Purl:
Affected ranges
Affected versions
v9.3.1-rc2
v9.3.1-rc1
v9.3.0-rc2
v9.3.0
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
