In Mattermost versions 9.8.x <= 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2 and 9.5.x <= 9.5.5 a medium severity vulnerability CVE-2024-39830 was detected. When shared channels are enabled, variable-time token comparison allows attackers to retrieve tokens via timing attacks, exposing security-relevant information to unauthorized actors. There is no solution for this yet. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-39830.
Read more CommunicationIn Discourse version 3.2.3 a medium severity vulnerability CVE-2024-35234 was detected. This vulnerability allows attackers to use scripts in the user’s browsers. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-35234/.
Read more CommunicationIn Discourse version 3.2.3 a medium severity vulnerability CVE-2024-37157 was detected. This vulnerability allows attackers access to sensitive data. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-37157/.
Read more CommunicationIn Discourse version 3.2.3 a low severity vulnerability CVE-2024-36122 was detected. This vulnerability allows attackers to see a user’s email address. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-36122/.
Read more CommunicationIn Discourse version 3.2.3 a medium severity vulnerability CVE-2024-36113 was detected. This vulnerability allows attackers to suspend other staff users and block their login. There is no solution to this yet. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-36113/.
Read more CommunicationIn Discourse prior to version 3.2.3 a high severity vulnerability CVE-2024-35227 was detected. Malicious URLs disrupt the platform due to improper input validation, risking unsafe data processing. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-35227.
Read more CommunicationIn Mattermost all versions through 5.7.0 a medium severity vulnerability CVE-2024-37182 was detected. This flaw allows attackers to open external links without permission, potentially forcing your computer to run harmful programs. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-37182/.
Read more CommunicationIn Mattermost Desktop App versions <=5.7.0 a low severity vulnerability CVE-2024-36287 was detected. This issue happens because Electron debug flags are left enabled, allowing users to bypass macOS's TCC (Transparency, Consent, and Control) restrictions. To lower this risk, update to a newer version. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-36287.
Read more CommunicationIn Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 a medium severity vulnerability CVE-2024-5272 was detected. The “custom_playbooks_playbook_run_updated” webhook event doesn’t restrict its audience, so a guest in a linked channel can view all details of a playbook run after it’s finished. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-5272.
Read more Communication