PT-2024-2030 · Mattermost · Mattermost

Bharat

·

Published

2024-02-29

·

Updated

2025-05-12

·

CVE-2024-23488

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Mattermost versions prior to v8.1.9
Description The issue is related to inadequate access control in Mattermost, allowing remote attackers to gain unauthorized access to files in archived channels. Specifically, members can access files attached to posts in archived channels even when the "Allow users to view archived channels" option is disabled.
Recommendations For versions prior to v8.1.9, update to version v8.1.9 or later to resolve the issue. As a temporary workaround, consider restricting access to archived channels and their attached files until the update is applied.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-01906
CVE-2024-23488
GHSA-XGXJ-J98C-59RV
GO-2024-2595

Affected Products

Mattermost