In Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, and 9.8.x <= 9.8.1 a medium severity vulnerability CVE-2024-41162 was detected. This product doesn’t prevent remote modification of local channels when shared channels are enabled, allowing a malicious user to make any local channel read-only. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-41162.
Read more CommunicationIn Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, and 9.8.x <= 9.8.1 a high severity vulnerability CVE-2024-39274 was detected. This vulnerability allows remote attackers to add users to arbitrary teams and channels. To fix this problem, users should upgrade Mattermost to versions 9.9.1, 9.5.7, 9.7.6, and 9.8.2 and later. For more details, https://avd.aquasec.com/nvd/2024/cve-2024-39274.
Read more CommunicationIn Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, and 9.8.x <= 9.8.1 a high severity vulnerability CVE-2024-36492 was detected. This vulnerability allows a malicious remote attacker to overwrite an existing local user by exploiting the system’s failure to disallow the modification of local users when syncing users in shared channels. To fix this problem, users should upgrade Mattermost to versions 9.9.1, 9.5.7, 9.7.6, and 9.8.2 and later. For more details, https://avd.aquasec.com/nvd/2024/cve-2024-36492.
Read more CommunicationIn Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, and 9.8.x <= 9.8.1 a high severity vulnerability CVE-2024-39777 was detected. This vulnerability allows attackers to share local channels without admin consent by sending unsolicited invites with the ID of an existing local channel. To fix this problem, users should upgrade Mattermost to versions 9.9.1, 9.5.7, 9.7.6, and 9.8.2 and later. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-39777.
Read more CommunicationIn Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 a medium severity vulnerability CVE-2024-41144 was detected. The application doesn’t validate synced posts correctly when shared channels are enabled, letting a malicious user create, update, or delete posts in any channel. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-41144.
Read more CommunicationIn Discourse versions priorto 3.2.3 and 3.3.0.beta3 a medium severity vulnerability CVE-2024-37165 was detected. A flaw in the Onebox feature can allow harmful code to run if the data is not cleaned correctly. This issue only affects Discourse instances that have turned off the default Content Security Policy. This vulnerability is fixed in 3.2.3 and 3.3.0.beta3. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-37299.
Read more CommunicationIn Discourse versions prior to 3.2.5 and 3.3.0.beta5 a medium severity vulnerability CVE-2024-37299 was detected. Creating requests with very long tag group names can make a Discourse instance less available. This issue is resolved in versions 3.2.5 and 3.3.0.beta5. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-37299.
Read more CommunicationIn Discourse versions prior to 3.2.5 and 3.3.0.beta5 a medium severity vulnerability CVE-2024-39320 was detected. This vulnerability allows attackers to inject iframes from any domain, bypassing the intended restrictions enforced by the allowed_iframes setting. This vulnerability is fixed in 3.2.5 and 3.3.0.beta5. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-39320.
Read more CommunicationIn Mattermost versions before 2.16.0 a medium severity vulnerability CVE-2024-39767 was detected. This vulnerability allows attackers to send notifications from another server. There is no fix for this yet. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-39767/.
Read more Communication