In Mattermost in Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier a medium severity vulnerability CVE-2024-39400 was detected. This vulnerability allows admins to run harmful JavaScript in a user’s browser. It requires the user to click a malicious link and can seriously affect security, especially for other admin accounts. Update Adobe Commerce to the latest version to fix this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-3904.
Read more CommunicationIn Rocket.Chat versions prior to 6.10.1 a high severity vulnerability CVE-2024-39713 was detected. This vulnerability allows attackers to make the server send requests to unintended locations, potentially accessing or manipulating private information. To fix this problem, users should upgrade Rocket.Chat to version 6.10.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-37313.
Read more CommunicationIn Mattermost versions 9.9.x up to 9.9.0 and 9.5.x up to 9.5.6 a low severity vulnerability CVE-2024-41926 was detected. This vulnerability allows attackers to mislead user information by using fake server IDs. To fix this problem, users should upgrade Mattermost to version 10.0.0. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-41926.
Read more CommunicationIn Mattermost versions 9.9.x up to 9.9.0 and 9.5.x up to 9.5.6 a low severity vulnerability CVE-2024-39837 was detected. This vulnerability allows attackers to create unauthorized channels if shared channels are turned on, because the system doesn’t properly control who can create them. To fix this problem, users should upgrade Mattermost to version 10.0.0. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-39837.
Read more CommunicationIn Mattermost versions 9.9.x up to 9.9.0 and 9.5.x up to 9.5.6 a low severity vulnerability CVE-2024-39832 was detected. This vulnerability allows attackers to create unauthorized channels if shared channels are turned on, because the system doesn’t properly control who can create them. To fix this problem, users should upgrade Mattermost to versions 9.5.7, 9.7.6, 9.8.2, and 9.9.1. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-39832.
Read more CommunicationIn Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 a medium severity vulnerability CVE-2024-39839 was detected. This vulnerability allows a remote user set their username to anything they want, which can then be synced to the local server if they haven’t been synced before. To fix this problem, users should upgrade Mattermost to versions 9.9.1, 9.5.7, 9.7.6, and 9.8.2 and later. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-39839.
Read more CommunicationIn Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6 a low severity vulnerability CVE-2024-29977 was detected. This vulnerability allows attackers to create arbitrary reactions on any posts in shared channels due to improper validation of synced reactions. To fix this problem, users should upgrade Mattermost to versions 9.9.1 and 9.5.7 and later. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-29977.
Read more CommunicationIn Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, and 9.8.x <= 9.8.1 a medium severity vulnerability CVE-2024-41162 was detected. This product doesn’t prevent remote modification of local channels when shared channels are enabled, allowing a malicious user to make any local channel read-only. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-41162.
Read more CommunicationIn Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, and 9.8.x <= 9.8.1 a high severity vulnerability CVE-2024-39274 was detected. This vulnerability allows remote attackers to add users to arbitrary teams and channels. To fix this problem, users should upgrade Mattermost to versions 9.9.1, 9.5.7, 9.7.6, and 9.8.2 and later. For more details, https://avd.aquasec.com/nvd/2024/cve-2024-39274.
Read more Communication