In Mattermost versions from 9.5.0 through 9.5.3, 9.7.0, 9.7.1 and from 8.1.0 through 8.1.12 a medium severity vulnerability CVE-2024-34029 was detected. This flaw lets unauthorized users see AD/LDAP group members linked to a team by adding the group to a channel. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-34029/.
Read more CommunicationIn Mattermost versions from 9.5.0 through 9.5.3, 9.6.0, 9.6.1, 9.7.0, 9.7.1 and from 8.1.0 through 8.1.12 a medium severity vulnerability CVE-2024-29215 was detected. It lets users run slash commands in channels they aren’t members of by linking a playbook run to the channel. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-29215/.
Read more CommunicationIn Mattermost versions from 9.5.x before 9.5.3, from 9.7.x before 9.7.1 and from 8.1.x before 8.1.12 a medium severity vulnerability CVE-2024-34029 was detected. The /api/v4/groups//channels//link endpoint has a permission issue. Users can see members of an AD/LDAP group linked to a team by adding the group to a channel, even if they shouldn’t have access. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-34029.
Read more CommunicationIn Mattermost versions 9.6.0 and 8.1.11 a medium severity vulnerability CVE-2024-31859 was detected. This vulnerability allows attackers to get the admin role. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-31859/.
Read more CommunicationIn Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1, and 8.1.x <= 8.1.12 a medium severity vulnerability CVE-2024-36255 was detected. This flaw lets attackers run task commands as other users by creating fake post actions that trigger unexpected commands in any channel. The web application does not properly check user input. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-36255/.
Read more CommunicationIn Mattermost versions from 9.5.x before 9.5.3, from 9.6.x before 9.6.1 and from 8.1.x before 8.1.12 a medium severity vulnerability CVE-2024-32045 was detected. The problem is due to inadequate access controls, allowing users to link playbook runs to private channels they shouldn’t access. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-32045.
Read more CommunicationIn Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 a critical security vulnerability CVE-2024-36241 was detected. This vulnerability allows attackers to view arbitrary post contents via a slash command. The system must have safe areas with trust boundaries to address this issue. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-36241.
Read more CommunicationIn Mattermost versions from 9.5.0 through 9.5.3, 9.6.0, 9.6.1 and from 8.1.0 through 8.1.12 a medium severity vulnerability CVE-2024-34152 was detected. It allows a guest to view the details of a public playbook by making a specific server request. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-34152/.
Read more CommunicationIn Mattermost Server versions 9.5.x before 9.5.2, 9.4.x before 9.4.4, 9.3.x before 9.3.3, and 8.1.x before 8.1.11 a medium severity vulnerability CVE-2024-28949 was detected. Failure to limit user preferences allows attackers to send a large volume, potentially causing denial of service by controlling a limited resource and exhausting available resources. To fix this issue, users should upgrade Mattermost to versions 8.1.11, 9.3.3, 9.4.4, 9.5.2 or 9.6.0. For more information, visit https://avd.aquasec.com/nvd/2024/cve-2024-28949/.
Read more Communication