PT-2024-39459 · Mattermost · Mattermost

Lorenzo Gallegos

·

Published

2024-09-26

·

Updated

2024-09-30

·

CVE-2024-9155

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Mattermost versions 9.5.x through 9.5.8 Mattermost versions 9.9.x through 9.9.2 Mattermost versions 9.10.x through 9.10.1
Description The issue allows an attacker to view unlinked channel files in channels they are a member of, due to a failure to limit access to these files. This is possible because the affected versions of Mattermost do not restrict access to channels files that have not been linked to a post.
Recommendations For versions 9.5.x through 9.5.8, update to a version later than 9.5.8 to resolve the issue. For versions 9.9.x through 9.9.2, update to a version later than 9.9.2 to resolve the issue. For versions 9.10.x through 9.10.1, update to a version later than 9.10.1 to resolve the issue.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-9155

Affected Products

Mattermost