In Rocket.Chat versions 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier a medium severity vulnerability CVE-2024-46935 was detected. This vulnerability allows attackers to crash the Rocket.Chat workspace by sending specially crafted messages, potentially causing a denial of service (DoS). To fix this problem, users should upgrade to version 6.13.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-46935.
Read more CommunicationIn Mattermost Desktop App versions 5.8.0 and earlier a medium severity vulnerability CVE-2024-45835 was detected. This vulnerability allows attackers to gather Chromium cookies or exploit other misconfigurations through remote or local access due to insufficient configuration of Electron Fuses. To fix this issue, it is recommended to update to versions later than 5.8.0 for the Desktop App and versions earlier than 5.9.0 for the Mattermost Server. For more details, visit https://avd.aquasec.com/nvd/cve-2024-45835.
Read more CommunicationIn Mattermost Desktop App versions 5.8.0 and earlier a medium severity vulnerability CVE-2024-39772 was detected. This vulnerability allows attackers to silently capture high-quality screenshots via JavaScript APIs due to a failure in safeguarding screen capture functionality. To fix this issue, users must upgrade to version 5.9.0 or later. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-39772.
Read more CommunicationIn Mattermost Desktop App versions 5.8.0 and earlier a medium severity vulnerability CVE-2024-39613 was detected. This vulnerability allows a local attacker to exploit the failure to specify an absolute path when searching for cmd.exe, enabling them to place a malicious cmd.exe file in the user’s Downloads folder and execute remote code. To fix this issue, users must upgrade to version 5.9.0 or later. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-39613.
Read more CommunicationIn Mattermost Mobile Apps versions up to 2.18.0 a medium severity vulnerability CVE-2024-45833 was detected. This issue allows attackers to access passwords saved in the dictionary if the Swiftkey keyboard is being used, the password includes a special character, and password masking is turned off. To fix this issue, users should upgrade Mattermost to 2.19.0 version. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-45833.
Read more CommunicationIn Mattermost Desktop App versions up to 5.8.0 a medium severity vulnerability CVE-2024-39613 was detected. This vulnerability allows local attackers to execute remote code by placing a malicious cmd.exe file in the Downloads folder on a user’s machine. To fix this issue, users should upgrade Mattermost to 5.9.0 version. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-39613.
Read more CommunicationIn Mattermost Desktop App versions up to and including 5.8.0 a medium severity vulnerability CVE-2024-39613 was found. This issue allows local attackers to run remote code by placing a malicious cmd.exe file in the Downloads folder on a user’s machine. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-39613.
Read more CommunicationIn Discourse Calendar plugin versions prior to 0.5 a medium severity vulnerability CVE-2024-45303 was detected. This vulnerability allows attackers to perform Cross-Site Scripting (XSS) attacks by exploiting dynamic calendar event names. This issue affects sites with modified or disabled default Content Security Policy in Discourse. To address this issue users should update to version 0.5 of the Discourse Calendar plugin. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-45303.
Read more CommunicationIn WP Discourse in all versions up to, and including 2.5.1 a medium severity vulnerability CVE-2024-35168 was detected. This vulnerability allows authenticated users with Subscriber-level access or higher to perform unauthorized actions due to a missing capability check. To fix this problem, users should upgrade WP Discourse to version 2.5.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-35168.
Read more Communication