Mattermost versions 9.5.x <= 9.5.8 fail to properly authorize access to archived channels when viewing archived channels is disabled, which allows an attacker to view posts and files of archived channels via file links.
References
Link | Resource |
---|---|
https://mattermost.com/security-updates | Vendor Advisory |
Configurations
History
26 Sep 2024, 18:42
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.3 |
First Time |
Mattermost
Mattermost mattermost Server |
|
CWE | NVD-CWE-noinfo | |
References | () https://mattermost.com/security-updates - Vendor Advisory | |
CPE | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* |
26 Sep 2024, 13:32
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
26 Sep 2024, 08:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-09-26 08:15
Updated : 2024-09-26 18:42
NVD link : CVE-2024-47145
Mitre link : CVE-2024-47145
CVE.ORG link : CVE-2024-47145
JSON object : View
Products Affected
mattermost
- mattermost_server
CWE