PT-2024-27360 · Mattermost · Mattermost Desktop App

Gee-Netics

·

Published

2024-06-14

·

Updated

2024-08-07

·

CVE-2024-37182

CVSS v3.1

4.7

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Mattermost Desktop App versions <=5.7.0
Description The issue allows a remote attacker to force a victim to run arbitrary programs on their system via custom URI schemes, due to the application's failure to correctly prompt for permission when opening external URLs.
Recommendations For Mattermost Desktop App versions <=5.7.0, update to a version greater than 5.7.0 to resolve the issue. As a temporary workaround, consider disabling the handling of custom URI schemes in the application until a patch is available. Restrict access to external URLs to minimize the risk of exploitation. Avoid using the Mattermost Desktop App to open external URLs from untrusted sources until the issue is resolved.

Fix

Protection Mechanism Failure

Weakness Enumeration

Related Identifiers

CVE-2024-37182
GHSA-HVXG-77MG-VRVP

Affected Products

Mattermost Desktop App