In Mattermost all versions through 5.7.0 a medium severity vulnerability CVE-2024-37182 was detected. This flaw allows attackers to open external links without permission, potentially forcing your computer to run harmful programs. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-37182/.
Read more CommunicationIn Mattermost Desktop App versions <=5.7.0 a low severity vulnerability CVE-2024-36287 was detected. This issue happens because Electron debug flags are left enabled, allowing users to bypass macOS's TCC (Transparency, Consent, and Control) restrictions. To lower this risk, update to a newer version. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-36287.
Read more CommunicationIn Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 a medium severity vulnerability CVE-2024-5272 was detected. The “custom_playbooks_playbook_run_updated” webhook event doesn’t restrict its audience, so a guest in a linked channel can view all details of a playbook run after it’s finished. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-5272.
Read more CommunicationIn Mattermost versions from 9.5.0 through 9.5.3, 9.7.0, 9.7.1 and from 8.1.0 through 8.1.12 a medium severity vulnerability CVE-2024-34029 was detected. This flaw lets unauthorized users see AD/LDAP group members linked to a team by adding the group to a channel. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-34029/.
Read more CommunicationIn Mattermost versions from 9.5.0 through 9.5.3, 9.6.0, 9.6.1, 9.7.0, 9.7.1 and from 8.1.0 through 8.1.12 a medium severity vulnerability CVE-2024-29215 was detected. It lets users run slash commands in channels they aren’t members of by linking a playbook run to the channel. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-29215/.
Read more CommunicationIn Mattermost versions from 9.5.x before 9.5.3, from 9.7.x before 9.7.1 and from 8.1.x before 8.1.12 a medium severity vulnerability CVE-2024-34029 was detected. The /api/v4/groups//channels//link endpoint has a permission issue. Users can see members of an AD/LDAP group linked to a team by adding the group to a channel, even if they shouldn’t have access. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-34029.
Read more CommunicationIn Mattermost versions 9.6.0 and 8.1.11 a medium severity vulnerability CVE-2024-31859 was detected. This vulnerability allows attackers to get the admin role. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-31859/.
Read more CommunicationIn Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1, and 8.1.x <= 8.1.12 a medium severity vulnerability CVE-2024-36255 was detected. This flaw lets attackers run task commands as other users by creating fake post actions that trigger unexpected commands in any channel. The web application does not properly check user input. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-36255/.
Read more CommunicationIn Mattermost versions from 9.5.x before 9.5.3, from 9.6.x before 9.6.1 and from 8.1.x before 8.1.12 a medium severity vulnerability CVE-2024-32045 was detected. The problem is due to inadequate access controls, allowing users to link playbook runs to private channels they shouldn’t access. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-32045.
Read more Communication