In Discourse versions prior to 3.2.5 and 3.3.0.beta5 a medium severity vulnerability CVE-2024-37299 was detected. Creating requests with very long tag group names can make a Discourse instance less available. This issue is resolved in versions 3.2.5 and 3.3.0.beta5. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-37299.
Read more CommunicationIn Discourse versions prior to 3.2.5 and 3.3.0.beta5 a medium severity vulnerability CVE-2024-39320 was detected. This vulnerability allows attackers to inject iframes from any domain, bypassing the intended restrictions enforced by the allowed_iframes setting. This vulnerability is fixed in 3.2.5 and 3.3.0.beta5. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-39320.
Read more CommunicationIn Mattermost versions before 2.16.0 a medium severity vulnerability CVE-2024-39767 was detected. This vulnerability allows attackers to send notifications from another server. There is no fix for this yet. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-39767/.
Read more CommunicationIn Mattermost Mobile Apps versions 2.16.0 and earlier a medium severity vulnerability CVE-2024-32945 was detected. This vulnerability allows attackers to gain unauthorized access to sensitive data by exploiting a vulnerability in the system. To fix this problem, users should upgrade Mattermost Mobile Apps to version 2.17.0 and higher. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-32945.
Read more CommunicationIn Rocket.Chat a medium severity vulnerability CVE-2024-37405 was detected. This vulnerability allows attackers to access sensitive data. There is no fix to this yet. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-37405/.
Read more CommunicationIn Discourse versions before 3.2.3 a medium severity vulnerability CVE-2024-38360 was detected. This vulnerability allows attackers to reduce the availability of a Discourse instance. To address this issue, users should update to version 3.2.3. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-38360/.
Read more CommunicationIn Mattermost versions from 9.5.5 to 9.8.0 a medium severity vulnerability CVE-2024-6428 was detected. This vulnerability allows attackers to create users and steal the data. There is no solution to this yet. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-6428/.
Read more CommunicationIn Mattermost versions 9.5.x <= 9.5.5 and 9.8.0 a medium severity vulnerability CVE-2024-0690 was detected. The RemoteClusterFrame payloads are not properly sanitized before being logged in the audit logs. This vulnerability allows a high-privileged attacker with access to the audit logs to read message contents. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-39353.
Read more CommunicationIn Mattermost versions 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2 and 9.5.x <= 9.5.5 a medium severity vulnerability CVE-2024-39361 was detected. It allows users to specify a RemoteId and post ID, letting attackers create posts with user-defined IDs. This can disrupt channel or thread functionality. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-39361.
Read more Communication