PT-2024-2030 · Mattermost · Mattermost
Bharat
·
Published
2024-02-29
·
Updated
2025-05-12
·
CVE-2024-23488
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Mattermost versions prior to v8.1.9
Description
The issue is related to inadequate access control in Mattermost, allowing remote attackers to gain unauthorized access to files in archived channels. Specifically, members can access files attached to posts in archived channels even when the "Allow users to view archived channels" option is disabled.
Recommendations
For versions prior to v8.1.9, update to version v8.1.9 or later to resolve the issue. As a temporary workaround, consider restricting access to archived channels and their attached files until the update is applied.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mattermost