PT-2024-31806 · Mattermost · Mattermost

Doyensec

+1

·

Published

2024-09-26

·

Updated

2024-09-27

·

CVE-2024-45843

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Mattermost versions 9.5.x through 9.5.8
Description: The issue arises from Mattermost's failure to include the metadata endpoints of Oracle Cloud and Alibaba in the SSRF denylist, potentially allowing an attacker to cause a server-side request forgery (SSRF) if Mattermost is deployed in Oracle Cloud or Alibaba. This could enable an attacker to remotely manipulate server requests.
Recommendations: For Mattermost versions 9.5.x through 9.5.8, upgrade Mattermost immediately to mitigate the risk of server-side request forgery. As a temporary workaround, consider restricting access to the metadata endpoints of Oracle Cloud and Alibaba to minimize the risk of exploitation.

Fix

SSRF

Weakness Enumeration

Related Identifiers

BIT-MATTERMOST-2024-45843
CVE-2024-45843

Affected Products

Mattermost