Mattermost Vulnerability Allows Access to Private Channels
CVE-2024-42000

4.3MEDIUM

Key Information:

Vendor
Mattermost
Vendor
CVE Published:
9 November 2024

Summary

Certain versions of Mattermost exhibit a flaw in their authorization process related to the API endpoint /api/v4/channels. This vulnerability allows users or System Managers with 'Read Groups' permission, but without actual channel access, to retrieve information about private channels they do not belong to. Such unauthorized access can lead to potential privacy violations and compromise sensitive information, highlighting the importance of reviewing access controls and security measures in the affected versions.

Affected Version(s)

Mattermost 9.10.0 <= 9.10.2

Mattermost 9.11.0 <= 9.11.1

Mattermost 9.5.0 <= 9.5.9

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

othman (3thm4n)
.