PT-2024-27360 · Mattermost · Mattermost Desktop App

·

CVE-2024-37182

·

Published

2024-06-14

·

Updated

2024-08-07

CVSS v3.1

4.7

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Mattermost Desktop App versions <=5.7.0
Description The issue allows a remote attacker to force a victim to run arbitrary programs on their system via custom URI schemes, due to the application's failure to correctly prompt for permission when opening external URLs.
Recommendations For Mattermost Desktop App versions <=5.7.0, update to a version greater than 5.7.0 to resolve the issue. As a temporary workaround, consider disabling the handling of custom URI schemes in the application until a patch is available. Restrict access to external URLs to minimize the risk of exploitation. Avoid using the Mattermost Desktop App to open external URLs from untrusted sources until the issue is resolved.

Exploit

Fix

DoS

Protection Mechanism Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-37182
GHSA-HVXG-77MG-VRVP

Affected Products

Mattermost Desktop App