In Mattermost Mobile Apps versions 2.16.0 and earlier a medium severity vulnerability CVE-2024-32945 was detected. This vulnerability allows attackers to gain unauthorized access to sensitive data by exploiting a vulnerability in the system. To fix this problem, users should upgrade Mattermost Mobile Apps to version 2.17.0 and higher. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-32945.
Read more CommunicationIn Rocket.Chat a medium severity vulnerability CVE-2024-37405 was detected. This vulnerability allows attackers to access sensitive data. There is no fix to this yet. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-37405/.
Read more CommunicationIn Discourse versions before 3.2.3 a medium severity vulnerability CVE-2024-38360 was detected. This vulnerability allows attackers to reduce the availability of a Discourse instance. To address this issue, users should update to version 3.2.3. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-38360/.
Read more CommunicationIn Mattermost versions from 9.5.5 to 9.8.0 a medium severity vulnerability CVE-2024-6428 was detected. This vulnerability allows attackers to create users and steal the data. There is no solution to this yet. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-6428/.
Read more CommunicationIn Mattermost versions 9.5.x <= 9.5.5 and 9.8.0 a medium severity vulnerability CVE-2024-0690 was detected. The RemoteClusterFrame payloads are not properly sanitized before being logged in the audit logs. This vulnerability allows a high-privileged attacker with access to the audit logs to read message contents. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-39353.
Read more CommunicationIn Mattermost versions 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2 and 9.5.x <= 9.5.5 a medium severity vulnerability CVE-2024-39361 was detected. It allows users to specify a RemoteId and post ID, letting attackers create posts with user-defined IDs. This can disrupt channel or thread functionality. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-39361.
Read more CommunicationIn Mattermost versions 9.5.x <= 9.5.5 and 9.8.0 a medium severity vulnerability CVE-2024-36257 was detected. The security issue is observed: one server can change the profile pictures of users on another server, even though they’re not connected directly. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-36257.
Read more CommunicationIn Mastodon versions from 2.6.0 to 4.1.18 a high severity vulnerability CVE-2024-37903 was detected. This vulnerability allows attackers access to sensitive data. To fix this issue, users should update Mastodon to versions 4.2.10. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-37903/.
Read more CommunicationIn Mattermost versions 9.8.x <= 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2 and 9.5.x <= 9.5.5 a medium severity vulnerability CVE-2024-39830 was detected. When shared channels are enabled, variable-time token comparison allows attackers to retrieve tokens via timing attacks, exposing security-relevant information to unauthorized actors. There is no solution for this yet. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-39830.
Read more Communication