VDB
BIT-mattermost-2024-42406
BIT-mattermost-2024-42406
PUBLISHED
CVSS 5.400000095367432 MEDIUM
Mattermost versions 9.11.x <= 9.11.0, 9.10.x <= 9.10.1, 9.9.x <= 9.9.2 and 9.5.x <= 9.5.8 fail to properly authorize requests when viewing archived channels is disabled, which allows an attacker to retrieve post and file information about archived channels. Examples are flagged or unread posts as well as files.
Risk Scores
CVSS 3.1
5.400000095367432
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | mattermost | 9.5.0, 9.9.0, 9.10.0 |
Timeline
- Oct 2, 2024 CVE Published
- Apr 3, 2025 CVE Updated