PT-2024-18446 · Mattermost · Mattermost

Juho Nurminen

·

Published

2024-02-29

·

Updated

2024-12-16

·

CVE-2024-1952

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Mattermost versions 8.1.x through 8.1.8
Description The issue allows an authenticated attacker who can control the update of an ephemeral post to access individual posts' contents in channels they are not a member of. This is due to a failure to sanitize data associated with permalinks when a plugin updates an ephemeral post.
Recommendations For Mattermost versions 8.1.x through 8.1.8, update to version 8.1.9 or later to resolve the issue. As a temporary workaround, consider restricting the use of plugins that update ephemeral posts until a patch is available. Additionally, restrict access to sensitive channels to minimize the risk of exploitation.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

BIT-MATTERMOST-2024-1952
CVE-2024-1952
GHSA-R4FM-G65H-CR54
GO-2024-2635

Affected Products

Mattermost