Mattermost versions 9.6.x <= 9.6.0, 9.5.x <= 9.5.2, 9.4.x <= 9.4.4 and 8.1.x <= 8.1.11 fail to remove detailed error messages in API requests even if the developer mode is off which allows an attacker to get information about the server such as the full path were files are stored
References
Configurations
No configuration.
History
21 Nov 2024, 09:14
Type | Values Removed | Values Added |
---|---|---|
References | () https://mattermost.com/security-updates - | |
Summary |
|
26 Apr 2024, 09:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-04-26 09:15
Updated : 2024-11-21 09:14
NVD link : CVE-2024-32046
Mitre link : CVE-2024-32046
CVE.ORG link : CVE-2024-32046
JSON object : View
Products Affected
No product.
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor