In Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 a medium severity vulnerability CVE-2024-41144 was detected. The application doesn’t validate synced posts correctly when shared channels are enabled, letting a malicious user create, update, or delete posts in any channel. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-41144.
Read more CommunicationIn Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, and 9.8.x <= 9.8.1 a medium severity vulnerability CVE-2024-41162 was detected. This product doesn’t prevent remote modification of local channels when shared channels are enabled, allowing a malicious user to make any local channel read-only. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-41162.
Read more CommunicationIn Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, and 9.8.x <= 9.8.1 a high severity vulnerability CVE-2024-39274 was detected. This vulnerability allows remote attackers to add users to arbitrary teams and channels. To fix this problem, users should upgrade Mattermost to versions 9.9.1, 9.5.7, 9.7.6, and 9.8.2 and later. For more details, https://avd.aquasec.com/nvd/2024/cve-2024-39274.
Read more CommunicationIn Discourse versions priorto 3.2.3 and 3.3.0.beta3 a medium severity vulnerability CVE-2024-37165 was detected. A flaw in the Onebox feature can allow harmful code to run if the data is not cleaned correctly. This issue only affects Discourse instances that have turned off the default Content Security Policy. This vulnerability is fixed in 3.2.3 and 3.3.0.beta3. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-37299.
Read more CommunicationIn Discourse versions prior to 3.2.5 and 3.3.0.beta5 a medium severity vulnerability CVE-2024-37299 was detected. Creating requests with very long tag group names can make a Discourse instance less available. This issue is resolved in versions 3.2.5 and 3.3.0.beta5. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-37299.
Read more CommunicationIn Discourse versions prior to 3.2.5 and 3.3.0.beta5 a medium severity vulnerability CVE-2024-39320 was detected. This vulnerability allows attackers to inject iframes from any domain, bypassing the intended restrictions enforced by the allowed_iframes setting. This vulnerability is fixed in 3.2.5 and 3.3.0.beta5. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-39320.
Read more CommunicationIn Mattermost versions before 2.16.0 a medium severity vulnerability CVE-2024-39767 was detected. This vulnerability allows attackers to send notifications from another server. There is no fix for this yet. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-39767/.
Read more CommunicationIn Mattermost Mobile Apps versions 2.16.0 and earlier a medium severity vulnerability CVE-2024-32945 was detected. This vulnerability allows attackers to gain unauthorized access to sensitive data by exploiting a vulnerability in the system. To fix this problem, users should upgrade Mattermost Mobile Apps to version 2.17.0 and higher. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-32945.
Read more CommunicationIn Rocket.Chat a medium severity vulnerability CVE-2024-37405 was detected. This vulnerability allows attackers to access sensitive data. There is no fix to this yet. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-37405/.
Read more Communication