In Mattermost Desktop App versions 5.8.0 and earlier a medium severity vulnerability CVE-2024-39613 was detected. This vulnerability allows a local attacker to exploit the failure to specify an absolute path when searching for cmd.exe, enabling them to place a malicious cmd.exe file in the user’s Downloads folder and execute remote code. To fix this issue, users must upgrade to version 5.9.0 or later. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-39613.
Read more CommunicationIn Mattermost Mobile Apps versions up to 2.18.0 a medium severity vulnerability CVE-2024-45833 was detected. This issue allows attackers to access passwords saved in the dictionary if the Swiftkey keyboard is being used, the password includes a special character, and password masking is turned off. To fix this issue, users should upgrade Mattermost to 2.19.0 version. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-45833.
Read more CommunicationIn Mattermost Desktop App versions up to 5.8.0 a medium severity vulnerability CVE-2024-39613 was detected. This vulnerability allows local attackers to execute remote code by placing a malicious cmd.exe file in the Downloads folder on a user’s machine. To fix this issue, users should upgrade Mattermost to 5.9.0 version. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-39613.
Read more CommunicationIn Mattermost Desktop App versions up to and including 5.8.0 a medium severity vulnerability CVE-2024-39613 was found. This issue allows local attackers to run remote code by placing a malicious cmd.exe file in the Downloads folder on a user’s machine. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-39613.
Read more CommunicationIn Discourse Calendar plugin versions prior to 0.5 a medium severity vulnerability CVE-2024-45303 was detected. This vulnerability allows attackers to perform Cross-Site Scripting (XSS) attacks by exploiting dynamic calendar event names. This issue affects sites with modified or disabled default Content Security Policy in Discourse. To address this issue users should update to version 0.5 of the Discourse Calendar plugin. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-45303.
Read more CommunicationIn WP Discourse in all versions up to, and including 2.5.1 a medium severity vulnerability CVE-2024-35168 was detected. This vulnerability allows authenticated users with Subscriber-level access or higher to perform unauthorized actions due to a missing capability check. To fix this problem, users should upgrade WP Discourse to version 2.5.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-35168.
Read more CommunicationIn Rocket.Chat Electron desktop application versions through 6.3.4 a low severity vulnerability CVE-2024-45621 was detected. This vulnerability allows attackers to execute stored XSS via links in an uploaded file. The issue arises from the failure to use a separate browser when encountering third-party external actions from PDF documents. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-45621.
Read more CommunicationIn Discourse a medium severity vulnerability CVE-2024-21658 was detected. This vulnerability allows a malicious actor to cause a Discourse instance to use excessive bandwidth and disk space. This issue has been patched in the main branch. To address this issue, users should upgrade to the latest version of Discourse. For more details, visit the https://nvd.nist.gov/vuln/detail/CVE-2024-21658.
Read more CommunicationIn Mattermost versions 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 a medium severity vulnerability CVE-2024-40884 was detected. This vulnerability allows attackers with team admin access to disable the invite link for new members, even if they don’t have permission to add team members, which can interfere with team management and control. To fix this problem, users should upgrade Mattermost to versions 9.5.8 and 9.10.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-40884.
Read more Communication