In Mattermost versions 9.5.x <= 9.5.5 and 9.8.0 a medium severity vulnerability CVE-2024-36257 was detected. The security issue is observed: one server can change the profile pictures of users on another server, even though they’re not connected directly. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-36257.
Read more CommunicationIn Mastodon versions from 2.6.0 to 4.1.18 a high severity vulnerability CVE-2024-37903 was detected. This vulnerability allows attackers access to sensitive data. To fix this issue, users should update Mastodon to versions 4.2.10. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-37903/.
Read more CommunicationIn Mattermost versions 9.8.x <= 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2 and 9.5.x <= 9.5.5 a medium severity vulnerability CVE-2024-39830 was detected. When shared channels are enabled, variable-time token comparison allows attackers to retrieve tokens via timing attacks, exposing security-relevant information to unauthorized actors. There is no solution for this yet. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-39830.
Read more CommunicationIn Mattermost versions 9.5.5 and 9.8.0 a medium severity vulnerability CVE-2024-39807 was detected. This vulnerability allows attackers to access sensitive data. There is no solution for this yet. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-39807.
Read more CommunicationIn Discourse version 3.2.3 a medium severity vulnerability CVE-2024-35234 was detected. This vulnerability allows attackers to use scripts in the user’s browsers. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-35234/.
Read more CommunicationIn Discourse version 3.2.3 a medium severity vulnerability CVE-2024-37157 was detected. This vulnerability allows attackers access to sensitive data. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-37157/.
Read more CommunicationIn Discourse version 3.2.3 a low severity vulnerability CVE-2024-36122 was detected. This vulnerability allows attackers to see a user’s email address. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-36122/.
Read more CommunicationIn Discourse version 3.2.3 a medium severity vulnerability CVE-2024-36113 was detected. This vulnerability allows attackers to suspend other staff users and block their login. There is no solution to this yet. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-36113/.
Read more CommunicationIn Discourse prior to version 3.2.3 a high severity vulnerability CVE-2024-35227 was detected. Malicious URLs disrupt the platform due to improper input validation, risking unsafe data processing. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-35227.
Read more Communication