CVE-2024-12247 MEDIUM

CVE-2024-12247: Improper propagation of permission scheme updates across cluster nodes

Vendor Mattermost
Product Mattermost
Weakness CWE-863 · Incorrect authorization
Published December 5, 2024
Last update December 5, 2024

CVSS base score

4.6/10
Attack vector Network
Attack complexity High
Privileges required Low
User interaction Required
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L

What the vulnerability does

01Description

Mattermost versions 9.7.x <= 9.7.5, 9.8.x <= 9.8.2 and 9.9.x <= 9.9.2 fail to properly propagate permission scheme updates across cluster nodes which allows a user to keep old permissions, even if the permission scheme has been updated.

Key dates

02Disclosure timeline

December 5, 2024 CVE published
December 5, 2024 Record updated