In Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 a critical security vulnerability CVE-2024-36241 was detected. This vulnerability allows attackers to view arbitrary post contents via a slash command. The system must have safe areas with trust boundaries to address this issue. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-36241.
Read more CommunicationIn Mattermost versions from 9.5.0 through 9.5.3, 9.6.0, 9.6.1 and from 8.1.0 through 8.1.12 a medium severity vulnerability CVE-2024-34152 was detected. It allows a guest to view the details of a public playbook by making a specific server request. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-34152/.
Read more CommunicationIn Mattermost Server versions 9.5.x before 9.5.2, 9.4.x before 9.4.4, 9.3.x before 9.3.3, and 8.1.x before 8.1.11 a medium severity vulnerability CVE-2024-28949 was detected. Failure to limit user preferences allows attackers to send a large volume, potentially causing denial of service by controlling a limited resource and exhausting available resources. To fix this issue, users should upgrade Mattermost to versions 8.1.11, 9.3.3, 9.4.4, 9.5.2 or 9.6.0. For more information, visit https://avd.aquasec.com/nvd/2024/cve-2024-28949/.
Read more CommunicationImproper Access Control in Mattermost Server versions 9.5.x before 9.5.2, 9.4.x before 9.4.4, 9.3.x before 9.3.3, and 8.1.x before 8.1.11 a medium severity vulnerability CVE-2024-29221 was detected. The issue allows unauthorized users to access sensitive information and perform actions they shouldn’t be able to. This vulnerability is resolved in Mattermost Server versions 8.1.11, 9.3.3, 9.4.4, or 9.5.2 or later. For more information, visit https://avd.aquasec.com/nvd/2024/cve-2024-29221/.
Read more Communication