Vulnerability in Mattermost Android Mobile Apps Leading to Local File Access
CVE-2024-11358
5.7MEDIUM
Summary
CVE-2024-11358 describes a high-risk vulnerability in the Mattermost Android Mobile Apps (versions 2.21.0 and earlier) due to a failure in properly configuring file providers. This security flaw allows an attacker with local access to the device to potentially exploit this weakness to access sensitive files through the misconfigured file provider. Organizations using these apps are advised to review their security policies and update to the latest version to mitigate this risk.
Affected Version(s)
Mattermost Android 0 <= 2.21.0
Mattermost Android 2.22.0
References
CVSS V3.1
Score:
5.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
BugSniper (bugsniper1081)