In Zulip version 8.3 a medium severity vulnerability CVE-2024-36624 was detected. This vulnerability allows attackers to exploit the application using Cross Site Scripting (XSS) techniques. No patched version has been officially released at this time. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-36624.
Read more CommunicationIn Zulip versions 8.0 to 8.3 a high severity vulnerability CVE-2024-36612 was detected. This vulnerability allows attackers to exploit a memory leak in the handling of popovers. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-36612.
Read more CommunicationIn Mattermost versions 10.0.x up to and including 10.0.1, 10.1.x up to and including 10.1.1, 9.11.x up to and including 9.11.3, 9.5.x up to and including 9.5.11 a high severity vulnerability CVE-2024-11599 was detected. This vulnerability allows unauthenticated users to bypass email domain restrictions during registration via crafted email input. To address this issue, users must upgrade to Mattermost versions 10.2.0, 10.0.2, 10.1.2, 9.11.4, 9.5.12 or higher. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-11599.
Read more CommunicationIn Mastodon versions 4.1.x prior to 4.1.17 and 4.2.x prior to 4.2.9 a high severity vulnerability CVE-2023-49952 was detected. This vulnerability allows attackers to bypass limits on how many requests they can make by sending a special request to the server. To fix this issue, users need to update to versions 4.2.9 or above. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2023-49952.
Read more CommunicationIn Mattermost versions 10.0.x ≤ 10.0.0 and 9.11.x ≤ 9.11.2 a medium severity vulnerability, CVE-2024-52032, was detected. This vulnerability allows attackers to retrieve the names of private channels they are not a member of when using the channel switcher feature, provided Elasticsearch v8 is enabled. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-52032.
Read more CommunicationIn Mattermost versions 9.10.x up to 9.10.2, 9.11.x up to 9.11.1, 9.5.x up to 9.5.9 and 10.0.x up to 10.0.0 a low severity vulnerability CVE-2024-42000 was detected. This vulnerability allows attackers with “Read Groups” permission, but without access to specific channels, to retrieve details about private channels they are not members of by sending a request to /api/v4/channels. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-42000.
In Mattermost versions 9.11.x up to 9.11.2 and 9.5.x up to 9.5.10 a low severity vulnerability CVE-2024-36250 was detected. This vulnerability allows attackers to reuse the MFA code within approximately 30 seconds, exploiting inadequate replay protection. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-36250.
Read more CommunicationIn Mattermost versions from 9.11.x prior to 9.11.1 and from 9.5.x prior to 9.5.9 a low severity vulnerability CVE-2024-10214 was detected. This vulnerability allows attackers to create two active sessions, increasing the chance of unauthorized access. To fix this issue, users should update Mattermost to versions 9.11.2, 9.5.10 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-10214.
Read more CommunicationIn Mattermost versions 9.10.0 to 9.10.2, 9.11.0 to 9.11.1, and 9.5.0 to 9.5.9 a medium severity vulnerability CVE-2024-50052 was found. This issue allows authenticated users to delete any post because the system fails to verify the message’s origin. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-50052.
Read more Communication