In Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, and 9.8.x <= 9.8.2 a medium severity vulnerability CVE-2024-32939 was detected. When shared channels are enabled, remote users’ original email addresses stored in user properties are not redacted, even when email visibility is configured to be hidden on the local server. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-32939.
Read more CommunicationIn Mattermost versions ≤ 1.0.0 a medium severity vulnerability CVE-2024-43105 was detected. This vulnerability allows a user to consume excessive resources by running the /export command multiple times at once. To fix this issue, users must upgrade Mattermost to version 1.0.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-43105.
In Mattermost versions 9.5.x <= 9.5.7 and 9.10.x <= 9.10.0 a medium severity vulnerability CVE-2024-43813 was detected. The system lacks proper access controls, letting any authenticated user, including guests, mark any channel in any team as read for any user. This can lead to unauthorized changes in user notifications and disrupt the user experience. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-43813.
Read more CommunicationIn Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.0, 9.8.x <= 9.8.2 a medium severity vulnerability CVE-2024-43780 was detected. This vulnerability allows a guest user with read access to upload files to a channel. To fix this issue, users must upgrade Mattermost to versions 9.5.8, 9.10.1, 9.9.2, 9.8.3. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-43780/.
Read more CommunicationIn Mattermost Plugin Channel Export versions before 1.0.0 a medium severity vulnerability CVE-2024-43105 was detected. This vulnerability allows attackers to overload the system by running the export command multiple times, which can slow down or crash the server. To fix this problem, users should upgrade Mattermost Plugin Channel Export to version 1.0.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-43105.
Read more CommunicationIn Mattermost in Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier a medium severity vulnerability CVE-2024-39400 was detected. This vulnerability allows admins to run harmful JavaScript in a user’s browser. It requires the user to click a malicious link and can seriously affect security, especially for other admin accounts. Update Adobe Commerce to the latest version to fix this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-3904.
Read more CommunicationIn Rocket.Chat versions prior to 6.10.1 a high severity vulnerability CVE-2024-39713 was detected. This vulnerability allows attackers to make the server send requests to unintended locations, potentially accessing or manipulating private information. To fix this problem, users should upgrade Rocket.Chat to version 6.10.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-37313.
Read more CommunicationIn Mattermost versions 9.9.x up to 9.9.0 and 9.5.x up to 9.5.6 a low severity vulnerability CVE-2024-41926 was detected. This vulnerability allows attackers to mislead user information by using fake server IDs. To fix this problem, users should upgrade Mattermost to version 10.0.0. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-41926.
Read more CommunicationIn Mattermost versions 9.9.x up to 9.9.0 and 9.5.x up to 9.5.6 a low severity vulnerability CVE-2024-39837 was detected. This vulnerability allows attackers to create unauthorized channels if shared channels are turned on, because the system doesn’t properly control who can create them. To fix this problem, users should upgrade Mattermost to version 10.0.0. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-39837.
Read more Communication