In Mattermost Desktop App versions up to 5.8.0 a medium severity vulnerability CVE-2024-39613 was detected. This vulnerability allows local attackers to execute remote code by placing a malicious cmd.exe file in the Downloads folder on a user’s machine. To fix this issue, users should upgrade Mattermost to 5.9.0 version. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-39613.
Read more CommunicationIn Mattermost Desktop App versions up to and including 5.8.0 a medium severity vulnerability CVE-2024-39613 was found. This issue allows local attackers to run remote code by placing a malicious cmd.exe file in the Downloads folder on a user’s machine. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-39613.
Read more CommunicationIn Discourse Calendar plugin versions prior to 0.5 a medium severity vulnerability CVE-2024-45303 was detected. This vulnerability allows attackers to perform Cross-Site Scripting (XSS) attacks by exploiting dynamic calendar event names. This issue affects sites with modified or disabled default Content Security Policy in Discourse. To address this issue users should update to version 0.5 of the Discourse Calendar plugin. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-45303.
Read more CommunicationIn WP Discourse in all versions up to, and including 2.5.1 a medium severity vulnerability CVE-2024-35168 was detected. This vulnerability allows authenticated users with Subscriber-level access or higher to perform unauthorized actions due to a missing capability check. To fix this problem, users should upgrade WP Discourse to version 2.5.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-35168.
Read more CommunicationIn Rocket.Chat Electron desktop application versions through 6.3.4 a low severity vulnerability CVE-2024-45621 was detected. This vulnerability allows attackers to execute stored XSS via links in an uploaded file. The issue arises from the failure to use a separate browser when encountering third-party external actions from PDF documents. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-45621.
Read more CommunicationIn Discourse a medium severity vulnerability CVE-2024-21658 was detected. This vulnerability allows a malicious actor to cause a Discourse instance to use excessive bandwidth and disk space. This issue has been patched in the main branch. To address this issue, users should upgrade to the latest version of Discourse. For more details, visit the https://nvd.nist.gov/vuln/detail/CVE-2024-21658.
Read more CommunicationIn Mattermost versions 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 a medium severity vulnerability CVE-2024-40884 was detected. This vulnerability allows attackers with team admin access to disable the invite link for new members, even if they don’t have permission to add team members, which can interfere with team management and control. To fix this problem, users should upgrade Mattermost to versions 9.5.8 and 9.10.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-40884.
Read more CommunicationIn Mattermost versions 9.5.x <= 9.5.7 and 9.10.x <= 9.10.0 a medium severity vulnerability CVE-2024-39810 was detected. The ElasticSearch configuration lacks time and size limits on the CA path file, allowing a user with console access to add files like /dev/zero, which can crash the application. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-39810.
Read more CommunicationIn Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, and 9.8.x <= 9.8.2 a medium severity vulnerability CVE-2024-39836 was detected. Mattermost versions have a vulnerability where remote or synthetic users can use munged email addresses from shared channels to create sessions and reset passwords if the emails are valid. To fix this problem, users should upgrade to version 9.11.0, 9.9.2, 9.5.8, 9.10.1, or 9.8.3. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-39836.
Read more Communication