VDB
BIT-mattermost-2024-45843
BIT-mattermost-2024-45843
PUBLISHED
CVSS 5.400000095367432 MEDIUM
Mattermost versions 9.5.x <= 9.5.8 fail to include the metadata endpoints of Oracle Cloud and Alibaba in the SSRF denylist, which allows an attacker to possibly cause an SSRF if Mattermost was deployed in Oracle Cloud or Alibaba.
Risk Scores
CVSS 3.1
5.400000095367432
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | mattermost | 9.5.0, 9.5.0, 9.5.0 |
Timeline
- Sep 27, 2024 CVE Published
- Apr 3, 2025 CVE Updated