CVE-2024-42406

Mattermost versions 9.11.x <= 9.11.0, 9.10.x <= 9.10.1, 9.9.x <= 9.9.2 and 9.5.x <= 9.5.8 fail to properly authorize requests when viewing archived channels is disabled, which allows an attacker to retrieve post and file information about archived channels. Examples are flagged or unread posts as well as files.
References
Link Resource
https://mattermost.com/security-updates Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
cpe:2.3:a:mattermost:mattermost_server:9.11.0:-:*:*:*:*:*:*
cpe:2.3:a:mattermost:mattermost_server:9.11.0:rc1:*:*:*:*:*:*
cpe:2.3:a:mattermost:mattermost_server:9.11.0:rc2:*:*:*:*:*:*
cpe:2.3:a:mattermost:mattermost_server:9.11.0:rc3:*:*:*:*:*:*

History

01 Oct 2024, 11:15

Type Values Removed Values Added
CPE cpe:2.3:a:mattermost:mattermost_server:9.11.0:rc3:*:*:*:*:*:*
cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
cpe:2.3:a:mattermost:mattermost_server:9.11.0:rc1:*:*:*:*:*:*
cpe:2.3:a:mattermost:mattermost_server:9.11.0:-:*:*:*:*:*:*
cpe:2.3:a:mattermost:mattermost_server:9.11.0:rc2:*:*:*:*:*:*
References () https://mattermost.com/security-updates - () https://mattermost.com/security-updates - Vendor Advisory
CWE NVD-CWE-noinfo
First Time Mattermost mattermost Server
Mattermost

26 Sep 2024, 13:32

Type Values Removed Values Added
Summary
  • (es) Las versiones 9.11.x &lt;= 9.11.0, 9.10.x &lt;= 9.10.1, 9.9.x &lt;= 9.9.2 y 9.5.x &lt;= 9.5.8 de Mattermost no autorizan correctamente las solicitudes cuando la visualización de canales archivados está deshabilitada, lo que permite a un atacante recuperar información de publicaciones y archivos sobre canales archivados. Algunos ejemplos son las publicaciones marcadas o no leídas, así como los archivos.

26 Sep 2024, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-26 08:15

Updated : 2024-10-01 11:15


NVD link : CVE-2024-42406

Mitre link : CVE-2024-42406

CVE.ORG link : CVE-2024-42406


JSON object : View

Products Affected

mattermost

  • mattermost_server
CWE
NVD-CWE-noinfo CWE-284

Improper Access Control