In Rocket.Chat Electron desktop application versions through 6.3.4 a low severity vulnerability CVE-2024-45621 was detected. This vulnerability allows attackers to execute stored XSS via links in an uploaded file. The issue arises from the failure to use a separate browser when encountering third-party external actions from PDF documents. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-45621.
Read more CommunicationIn Discourse a medium severity vulnerability CVE-2024-21658 was detected. This vulnerability allows a malicious actor to cause a Discourse instance to use excessive bandwidth and disk space. This issue has been patched in the main branch. To address this issue, users should upgrade to the latest version of Discourse. For more details, visit the https://nvd.nist.gov/vuln/detail/CVE-2024-21658.
Read more CommunicationIn Mattermost versions 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 a medium severity vulnerability CVE-2024-40884 was detected. This vulnerability allows attackers with team admin access to disable the invite link for new members, even if they don’t have permission to add team members, which can interfere with team management and control. To fix this problem, users should upgrade Mattermost to versions 9.5.8 and 9.10.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-40884.
Read more CommunicationIn Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, and 9.8.x <= 9.8.2 a medium severity vulnerability CVE-2024-39836 was detected. Mattermost versions have a vulnerability where remote or synthetic users can use munged email addresses from shared channels to create sessions and reset passwords if the emails are valid. To fix this problem, users should upgrade to version 9.11.0, 9.9.2, 9.5.8, 9.10.1, or 9.8.3. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-39836.
Read more CommunicationIn Mattermost versions 9.9.x ≤ 9.9.1, 9.5.x ≤ 9.5.7, 9.10.x ≤ 9.10.0, and 9.8.x ≤ 9.8.2 a medium severity vulnerability CVE-2024-40886 was detected. This vulnerability allows attackers to perform a one-click path traversal and launch a CSRF attack on the User Management page. To fix this problem, users should upgrade to version 9.11.0, 9.9.2, 9.5.8, 9.10.1, 9.8.3. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-40886.
Read more CommunicationIn Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 a medium severity vulnerability CVE-2024-42411 was detected. This vulnerability allows a user to manipulate the creation date in POST /api/v4/users tricking the admin into believing their account is much older. To fix this problem, users must upgrade to 9.11.0, 9.9.2, 9.5.8, 9.10.1, 9.8.3. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-42411.
In Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, and 9.8.x <= 9.8.2 a medium severity vulnerability CVE-2024-42497 was detected. This vulnerability allows attackers with read-only access to teams to escalate their permissions and make unauthorized changes to team data, potentially affecting the integrity and confidentiality of the Mattermost system. To fix this problem, users should upgrade Mattermost to versions 9.11.0, 9.9.2, 9.5.8, 9.10.1, and 9.8.3. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-42497.
In Mattermost versions 9.5.x <= 9.5.7 and 9.10.x <= 9.10.0 a medium severity vulnerability CVE-2024-39810 was detected. The ElasticSearch configuration lacks time and size limits on the CA path file, allowing a user with console access to add files like /dev/zero, which can crash the application. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-39810.
Read more CommunicationIn Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 a medium severity vulnerability CVE-2024-8071 was detected. This vulnerability allows attackers with certain permissions to elevate their privileges to become a system administrator, giving them full control over the Mattermost system. To fix this issue, users should upgrade Mattermost to versions 9.11.0, 9.9.2, 9.5.8, 9.10.1 and 9.8.3. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-8071.
Read more Communication