PT-2024-31806 · Mattermost · Mattermost
Doyensec
+1
·
Published
2024-09-26
·
Updated
2024-09-27
·
CVE-2024-45843
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Mattermost versions 9.5.x through 9.5.8
Description:
The issue arises from Mattermost's failure to include the metadata endpoints of Oracle Cloud and Alibaba in the SSRF denylist, potentially allowing an attacker to cause a server-side request forgery (SSRF) if Mattermost is deployed in Oracle Cloud or Alibaba. This could enable an attacker to remotely manipulate server requests.
Recommendations:
For Mattermost versions 9.5.x through 9.5.8, upgrade Mattermost immediately to mitigate the risk of server-side request forgery. As a temporary workaround, consider restricting access to the metadata endpoints of Oracle Cloud and Alibaba to minimize the risk of exploitation.
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mattermost