Mattermost Vulnerability Allows Access to Private Channels
CVE-2024-42000
4.3MEDIUM
Summary
Certain versions of Mattermost exhibit a flaw in their authorization process related to the API endpoint /api/v4/channels. This vulnerability allows users or System Managers with 'Read Groups' permission, but without actual channel access, to retrieve information about private channels they do not belong to. Such unauthorized access can lead to potential privacy violations and compromise sensitive information, highlighting the importance of reviewing access controls and security measures in the affected versions.
Affected Version(s)
Mattermost 9.10.0 <= 9.10.2
Mattermost 9.11.0 <= 9.11.1
Mattermost 9.5.0 <= 9.5.9
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
othman (3thm4n)