Proactive Insights and Support For Open-Source Applications
  • Applications
  • Platform
  • Support
  • Resources
    • 2025 OSS Research
    • FAQ
    • Newsflash
    • OSSpedia
    • How-to Guides
    • Case Studies
    • Articles
  • Company
    • About Us
    • The OSS in Hossted
  • Contact
Book a demo
Book a demo
  • Applications
  • Platform
  • Support
  • Resources
    • 2025 OSS Research
    • FAQ
    • Newsflash
    • OSSpedia
    • How-to Guides
    • Case Studies
    • Articles
  • Company
    • About Us
    • The OSS in Hossted
  • Contact
  • Home
  • Knowledge Base
  • Newsflash
  • Communication and Collaboration

Communication and Collaboration

All OSSpediaArticlesHow ToNewsflashCase Studies
Don't Miss out!
Join our newsletter for exclusive updates on open source innovations.

    Selected category
    • Communication
      • Communication
    • Communication and Collaboration
      • Communication
    • Specialized Software
      • Educational
      • Graphic Design
    • Business and Enterprise Solutions
      • Customer Service
      • Productivity
      • Supply Chain Management (SCM)
      • CRM
      • E-commerce
      • CMS
      • Marketing Automation
      • ERP
    • Project and Agile Management
      • Project Management
      • IT Business Management
    • Infrastructure and Network
      • CMS
      • Networking
      • Storage
      • Security
    • DevOps
      • DevOps
      • Mobile App Development
      • Backup and Recovery
      • Data Analytics
      • Web Development
      • Developer Stacks
      • Cloud Computing
      • Monitoring
      • Application Development
      • Developer Tools
    • Data Management and Analytics
      • Communication
      • Application Development
      • Analytics
      • Machine Learning
      • Database
      • Data Analytics
    2 Aug 2024 Communication and Collaboration
    Mattermost: Vulnerability in Shared Channels Allows Remote Modification of Local Channels

    In Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, and 9.8.x <= 9.8.1 a medium severity vulnerability CVE-2024-41162 was detected. This product doesn’t prevent remote modification of local channels when shared channels are enabled, allowing a malicious user to make any local channel read-only. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-41162.

    Read more
    Communication
    2 Aug 2024 Communication and Collaboration
    Mattermost: Unauthorized User Additions

    In Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, and 9.8.x <= 9.8.1 a high severity vulnerability CVE-2024-39274 was detected. This vulnerability allows remote attackers to add users to arbitrary teams and channels. To fix this problem, users should upgrade Mattermost to versions 9.9.1, 9.5.7, 9.7.6, and 9.8.2 and later. For more details, https://avd.aquasec.com/nvd/2024/cve-2024-39274.

    Read more
    Communication
    2 Aug 2024 Communication and Collaboration
    Mattermost: Critical Update to Prevent User Overwrite Vulnerability

    In Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, and 9.8.x <= 9.8.1 a high severity vulnerability CVE-2024-36492 was detected. This vulnerability allows a malicious remote attacker to overwrite an existing local user by exploiting the system’s failure to disallow the modification of local users when syncing users in shared channels. To fix this problem, users should upgrade Mattermost to versions 9.9.1, 9.5.7, 9.7.6, and 9.8.2 and later. For more details, https://avd.aquasec.com/nvd/2024/cve-2024-36492.

    Read more
    Communication
    2 Aug 2024 Communication and Collaboration
    Mattermost: Critical Update to Prevent Unauthorized Channel Sharing

    In Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, and 9.8.x <= 9.8.1 a high severity vulnerability CVE-2024-39777 was detected. This vulnerability allows attackers to share local channels without admin consent by sending unsolicited invites with the ID of an existing local channel. To fix this problem, users should upgrade Mattermost to versions 9.9.1, 9.5.7, 9.7.6, and 9.8.2 and later. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-39777.

    Read more
    Communication
    2 Aug 2024 Communication and Collaboration
    Mattermost: Security Vulnerability in Synced Posts Validation with Shared Channels

    In Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 a medium severity vulnerability CVE-2024-41144 was detected. The application doesn’t validate synced posts correctly when shared channels are enabled, letting a malicious user create, update, or delete posts in any channel. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-41144.

    Read more
    Communication
    31 Jul 2024 Communication and Collaboration
    Discourse: Cross-Site Scripting Vulnerability in Onebox Data

    In Discourse versions priorto 3.2.3 and 3.3.0.beta3 a medium severity vulnerability CVE-2024-37165 was detected. A flaw in the Onebox feature can allow harmful code to run if the data is not cleaned correctly. This issue only affects Discourse instances that have turned off the default Content Security Policy. This vulnerability is fixed in 3.2.3 and 3.3.0.beta3. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-37299.

    Read more
    Communication
    31 Jul 2024 Communication and Collaboration
    Discourse: Long Tag Names Can Cause Downtime

    In Discourse versions prior to 3.2.5 and 3.3.0.beta5 a medium severity vulnerability CVE-2024-37299 was detected. Creating requests with very long tag group names can make a Discourse instance less available. This issue is resolved in versions 3.2.5 and 3.3.0.beta5. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-37299.

    Read more
    Communication
    31 Jul 2024 Communication and Collaboration
    Discourse: Vulnerability Allowing Unauthorized Iframe Injection

    In Discourse versions prior to 3.2.5 and 3.3.0.beta5 a medium severity vulnerability CVE-2024-39320 was detected. This vulnerability allows attackers to inject iframes from any domain, bypassing the intended restrictions enforced by the allowed_iframes setting. This vulnerability is fixed in 3.2.5 and 3.3.0.beta5. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-39320.

    Read more
    Communication
    17 Jul 2024 Communication and Collaboration
    Mattermost: Attackers can send notifications from other servers

    In Mattermost versions before 2.16.0 a medium severity vulnerability CVE-2024-39767 was detected. This vulnerability allows attackers to send notifications from another server. There is no fix for this yet. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-39767/.

    Read more
    Communication
    Proactive Insights and Support For Open-Source Applications
    Contact us: Whatsapp
    Company
    • About Hossted
    • Data Processing Addendum
    Solutions
    • Applications
    • Support Plans
    • About Solution
    Resources
    • FAQ
    • Knowledge Base

    © HOSSTED 2026 All rights reserved

    • Privacy Policy
    • Terms and Conditions
    • Cookies Policy
    Cookie Settings

    We use cookies to measure marketing efforts and improve our services. Please review the cookie settings and confirm your choice.

    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}