Proactive Insights and Support For Open-Source Applications
  • Applications
  • Platform
  • Support
  • Resources
    • 2025 OSS Research
    • FAQ
    • Newsflash
    • OSSpedia
    • How-to Guides
    • Case Studies
    • Articles
  • Company
    • About Us
    • The OSS in Hossted
  • Contact
Book a demo
Book a demo
  • Applications
  • Platform
  • Support
  • Resources
    • 2025 OSS Research
    • FAQ
    • Newsflash
    • OSSpedia
    • How-to Guides
    • Case Studies
    • Articles
  • Company
    • About Us
    • The OSS in Hossted
  • Contact
  • Home
  • Knowledge Base
  • Newsflash
  • Communication and Collaboration

Communication and Collaboration

All OSSpediaArticlesHow ToNewsflashCase Studies
Don't Miss out!
Join our newsletter for exclusive updates on open source innovations.

    Selected category
    • Communication
      • Communication
    • Communication and Collaboration
      • Communication
    • Specialized Software
      • Educational
      • Graphic Design
    • Business and Enterprise Solutions
      • Customer Service
      • Productivity
      • Supply Chain Management (SCM)
      • CRM
      • E-commerce
      • CMS
      • Marketing Automation
      • ERP
    • Project and Agile Management
      • Project Management
      • IT Business Management
    • Infrastructure and Network
      • CMS
      • Networking
      • Storage
      • Security
    • DevOps
      • DevOps
      • Mobile App Development
      • Backup and Recovery
      • Data Analytics
      • Web Development
      • Developer Stacks
      • Cloud Computing
      • Monitoring
      • Application Development
      • Developer Tools
    • Data Management and Analytics
      • Communication
      • Application Development
      • Analytics
      • Machine Learning
      • Database
      • Data Analytics
    10 Oct 2024 Communication and Collaboration
    Discourse: Cache Poisoning Vulnerability via XHR Requests

    In Discourse version stable < 3.3.2, tests-passed < 3.4.0.beta2 a high severity vulnerability CVE-2024-47773 was detected. This vulnerability allows attackers to poison the cache with empty responses through repeated XHR requests, affecting anonymous visitors. It has been patched, and users should upgrade or disable the anonymous cache by setting DISCOURSE_DISABLE_ANON_CACHE. To fix this problem, users should upgrade to version stable >= 3.3.2, tests-passed >= 3.4.0.beta2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-47773.

    Read more
    Communication
    9 Oct 2024 Communication and Collaboration
    Rocket.Chat: Insufficient E2EE Password Entropy Vulnerability

    In Rocket.Chat versions prior to 4.5.1 a medium severity vulnerability CVE-2024-42027 was detected. Rocket.Chat Mobile’s E2EE password has insufficient entropy, allowing attackers to crack it with enough time and resources. To fix this problem, users should upgrade Rocket.Chat to version 4.5.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-42027.

    Read more
    Communication
    8 Oct 2024 Communication and Collaboration
    Discourse: JavaScript Execution Vulnerability in Disabled CSP Environments

    In Discourse versions before 2.9.0 a medium severity vulnerability CVE-2024-47772 was detected. This vulnerability allows attackers to run harmful JavaScript code in users’ browsers by sending a specially crafted chat message on Discourse sites with disabled security settings (CSP). To fix this issue, users should upgrade Discourse to version 2.9.0. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-47772.

    Read more
    Communication
    8 Oct 2024 Communication and Collaboration
    Discourse: Exposure of Hidden Tags Vulnerability

    In Discourse stable versions up to and including 3.3.1, beta versions up to and including 3.4.0.beta1, and tests-passed versions up to and including 3.4.0.beta1 a medium severity vulnerability CVE-2024-45297 was detected. This vulnerability allows attackers to view topics with a hidden tag in Discourse if they know the label or name of that tag, potentially exposing sensitive information. To fix this issue, users should upgrade Discourse to stable versions 3.3.2, beta versions 3.4.0.beta2, and tests-passed versions 3.4.0.beta2 and higher. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-45297.

    Read more
    Communication
    8 Oct 2024 Communication and Collaboration
    Discourse: Email Address Bypass Vulnerability

    In Discourse stable versions up to and including 3.3.1, beta versions up to and including 3.4.0.beta1, and tests-passed versions up to and including 3.4.0.beta1 a medium severity vulnerability CVE-2024-45051 was detected. This vulnerability allows attackers to use a maliciously crafted email address to bypass domain-based restrictions, potentially granting them unauthorized access to private sites, categories, and groups within Discourse. To fix this issue, users should upgrade Discourse to stable versions 3.3.2 and higher, beta versions 3.4.0.beta2 and higher, and tests-passed versions 3.4.0.beta2 and higher. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-45051.

    Read more
    Communication
    8 Oct 2024 Communication and Collaboration
    Discourse: Post Fetching Vulnerability

    In Discourse stable versions prior to 3.3.1 and tests-passed versions prior to 3.4.0.beta1 a medium severity vulnerability CVE-2024-43789 was detected. This vulnerability allows attackers to overload the Discourse system by creating a post with many replies and fetching them all at once. To fix this issue, users should upgrade Discourse to stable versions 3.3.1 and higher and tests-passed versions 3.4.0.beta1 and higher. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-43789.

    Read more
    Communication
    8 Oct 2024 Communication and Collaboration
    Mastodon: API Endpoint Rate Limiting Bypass Vulnerability

    In Mastodon versions prior to 4.1.16 and prior to 4.2.8 a medium severity vulnerability CVE-2024-34535 was detected. This vulnerability allows attackers to bypass API endpoint rate limiting by sending a specially crafted HTTP request header. To fix this issue, users should upgrade Mastodon to versions 4.1.17 or 4.2.9. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-34535.

    Read more
    Communication
    2 Oct 2024 Communication and Collaboration
    Mattermost: SSRF Vulnerability Threatens Data Security in Cloud Environments

    In Mattermost versions 9.5.x up to and including 9.5.8 a medium severity vulnerability CVE-2024-45843 was detected. This vulnerability allows attackers to exploit the lack of SSRF denylist entries for Oracle Cloud and Alibaba in Mattermost, potentially leading to unauthorized access to internal services or data. To fix this issue, users should upgrade Mattermost to versions 9.11.0 or 9.5.9. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-45843.

    Read more
    Communication
    2 Oct 2024 Communication and Collaboration
    Mattermost: Unauthorized Access to Archived Channel Files via File Links

    In Mattermost versions up to 9.5.x <= 9.5.8 a low severity vulnerability CVE-2024-47145 was detected. This vulnerability allows attackers to view posts and files from archived channels via file links, even when access to archived channels is disabled. To fix this problem, users should upgrade to version 9.11.0 and 9.5.9. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-47145.

    Read more
    Communication
    Proactive Insights and Support For Open-Source Applications
    Contact us: Whatsapp
    Company
    • About Hossted
    • Data Processing Addendum
    Solutions
    • Applications
    • Support Plans
    • About Solution
    Resources
    • FAQ
    • Knowledge Base

    © HOSSTED 2026 All rights reserved

    • Privacy Policy
    • Terms and Conditions
    • Cookies Policy
    Cookie Settings

    We use cookies to measure marketing efforts and improve our services. Please review the cookie settings and confirm your choice.

    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}