Mattermost Vulnerability Allows Access to Private Channels
CVE-2024-42000
What is CVE-2024-42000?
Certain versions of Mattermost exhibit a flaw in their authorization process related to the API endpoint /api/v4/channels. This vulnerability allows users or System Managers with 'Read Groups' permission, but without actual channel access, to retrieve information about private channels they do not belong to. Such unauthorized access can lead to potential privacy violations and compromise sensitive information, highlighting the importance of reviewing access controls and security measures in the affected versions.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Mattermost 9.10.0 <= 9.10.2
Mattermost 9.11.0 <= 9.11.1
Mattermost 9.5.0 <= 9.5.9
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved