VDB

BIT-mattermost-2024-45843

BIT-mattermost-2024-45843 PUBLISHED CVSS 5.400000095367432 MEDIUM

Mattermost versions 9.5.x <= 9.5.8 fail to include the metadata endpoints of Oracle Cloud and Alibaba in the SSRF denylist, which allows an attacker to possibly cause an SSRF if Mattermost was deployed in Oracle Cloud or Alibaba.

Risk Scores

CVSS 3.1
5.400000095367432
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersions
Bitnamimattermost9.5.0, 9.5.0, 9.5.0

Timeline

  • Sep 27, 2024 CVE Published
  • Apr 3, 2025 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›