CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 4.7. See the original NVD description below for full technical details.
CVE
CVE-2024-29221
Severity
MEDIUM
CVSS
4.7
EPSS
0.33%
Original NVD Description
Improper Access Control in Mattermost Server versions 9.5.x before 9.5.2, 9.4.x before 9.4.4, 9.3.x before 9.3.3, 8.1.x before 8.1.11 lacked proper access control in the `/api/v4/users/me/teams` endpoint allowing a team admin to get the invite ID of their team, thus allowing them to invite users, even if the "Add Members" permission was explicitly removed from team admins.
Related CVEs
Other vulnerabilities affecting the same vendor(s)