In Mattermost versions ≤ 1.0.0 a medium severity vulnerability CVE-2024-43105 was detected. This vulnerability allows a user to consume excessive resources by running the /export command multiple times at once. To fix this issue, users must upgrade Mattermost to version 1.0.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-43105.
In Mattermost Plugin Channel Export versions before 1.0.0 a medium severity vulnerability CVE-2024-43105 was detected. This vulnerability allows attackers to overload the system by running the export command multiple times, which can slow down or crash the server. To fix this problem, users should upgrade Mattermost Plugin Channel Export to version 1.0.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-43105.
Read more CommunicationIn Mattermost in Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier a medium severity vulnerability CVE-2024-39400 was detected. This vulnerability allows admins to run harmful JavaScript in a user’s browser. It requires the user to click a malicious link and can seriously affect security, especially for other admin accounts. Update Adobe Commerce to the latest version to fix this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-3904.
Read more CommunicationIn Rocket.Chat versions prior to 6.10.1 a high severity vulnerability CVE-2024-39713 was detected. This vulnerability allows attackers to make the server send requests to unintended locations, potentially accessing or manipulating private information. To fix this problem, users should upgrade Rocket.Chat to version 6.10.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-37313.
Read more CommunicationIn Mattermost versions 9.9.x up to 9.9.0 and 9.5.x up to 9.5.6 a low severity vulnerability CVE-2024-41926 was detected. This vulnerability allows attackers to mislead user information by using fake server IDs. To fix this problem, users should upgrade Mattermost to version 10.0.0. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-41926.
Read more CommunicationIn Mattermost versions 9.9.x up to 9.9.0 and 9.5.x up to 9.5.6 a low severity vulnerability CVE-2024-39837 was detected. This vulnerability allows attackers to create unauthorized channels if shared channels are turned on, because the system doesn’t properly control who can create them. To fix this problem, users should upgrade Mattermost to version 10.0.0. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-39837.
Read more CommunicationIn Mattermost versions 9.9.x up to 9.9.0 and 9.5.x up to 9.5.6 a low severity vulnerability CVE-2024-39832 was detected. This vulnerability allows attackers to create unauthorized channels if shared channels are turned on, because the system doesn’t properly control who can create them. To fix this problem, users should upgrade Mattermost to versions 9.5.7, 9.7.6, 9.8.2, and 9.9.1. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-39832.
Read more CommunicationIn Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 a medium severity vulnerability CVE-2024-39839 was detected. This vulnerability allows a remote user set their username to anything they want, which can then be synced to the local server if they haven’t been synced before. To fix this problem, users should upgrade Mattermost to versions 9.9.1, 9.5.7, 9.7.6, and 9.8.2 and later. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-39839.
Read more CommunicationIn Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6 a low severity vulnerability CVE-2024-29977 was detected. This vulnerability allows attackers to create arbitrary reactions on any posts in shared channels due to improper validation of synced reactions. To fix this problem, users should upgrade Mattermost to versions 9.9.1 and 9.5.7 and later. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-29977.
Read more Communication