PT-2024-30651 · Mattermost · Mattermost

Bharat

·

Published

2024-08-22

·

Updated

2024-10-17

·

CVE-2024-43780

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Mattermost versions 9.8.x through 9.8.2 Mattermost versions 9.5.x through 9.5.7 Mattermost versions 9.9.x through 9.9.1 Mattermost version 9.10.0
Description The issue is related to a failure in enforcing permissions, which allows a guest user with read access to upload files to a channel. This can potentially lead to unauthorized data uploads.
Recommendations For Mattermost versions 9.8.x through 9.8.2, update to a version later than 9.8.2 to resolve the issue. For Mattermost versions 9.5.x through 9.5.7, update to a version later than 9.5.7 to resolve the issue. For Mattermost versions 9.9.x through 9.9.1, update to a version later than 9.9.1 to resolve the issue. For Mattermost version 9.10.0, update to a version later than 9.10.0 to resolve the issue.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

BIT-MATTERMOST-2024-43780
CVE-2024-43780
GHSA-2JHX-W3VC-W59G
GO-2024-3089

Affected Products

Mattermost