In Mattermost versions from 9.5.x before 9.5.3, from 9.7.x before 9.7.1 and from 8.1.x before 8.1.12 a medium severity vulnerability CVE-2024-34029 was detected. The /api/v4/groups//channels//link endpoint has a permission issue. Users can see members of an AD/LDAP group linked to a team by adding the group to a channel, even if they shouldn’t have access. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-34029.
Read more CommunicationIn Mattermost versions 9.6.0 and 8.1.11 a medium severity vulnerability CVE-2024-31859 was detected. This vulnerability allows attackers to get the admin role. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-31859/.
Read more CommunicationIn Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1, and 8.1.x <= 8.1.12 a medium severity vulnerability CVE-2024-36255 was detected. This flaw lets attackers run task commands as other users by creating fake post actions that trigger unexpected commands in any channel. The web application does not properly check user input. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-36255/.
Read more CommunicationIn Mattermost versions from 9.5.x before 9.5.3, from 9.6.x before 9.6.1 and from 8.1.x before 8.1.12 a medium severity vulnerability CVE-2024-32045 was detected. The problem is due to inadequate access controls, allowing users to link playbook runs to private channels they shouldn’t access. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-32045.
Read more CommunicationIn Mattermost versions from 9.5.0 through 9.5.3, 9.6.0, 9.6.1 and from 8.1.0 through 8.1.12 a medium severity vulnerability CVE-2024-34152 was detected. It allows a guest to view the details of a public playbook by making a specific server request. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-34152/.
Read more CommunicationIn Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 a critical security vulnerability CVE-2024-36241 was detected. This vulnerability allows attackers to view arbitrary post contents via a slash command. The system must have safe areas with trust boundaries to address this issue. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-36241.
Read more CommunicationIn Mattermost Server versions 9.5.x before 9.5.2, 9.4.x before 9.4.4, 9.3.x before 9.3.3, and 8.1.x before 8.1.11 a medium severity vulnerability CVE-2024-28949 was detected. Failure to limit user preferences allows attackers to send a large volume, potentially causing denial of service by controlling a limited resource and exhausting available resources. To fix this issue, users should upgrade Mattermost to versions 8.1.11, 9.3.3, 9.4.4, 9.5.2 or 9.6.0. For more information, visit https://avd.aquasec.com/nvd/2024/cve-2024-28949/.
Read more CommunicationImproper Access Control in Mattermost Server versions 9.5.x before 9.5.2, 9.4.x before 9.4.4, 9.3.x before 9.3.3, and 8.1.x before 8.1.11 a medium severity vulnerability CVE-2024-29221 was detected. The issue allows unauthorized users to access sensitive information and perform actions they shouldn’t be able to. This vulnerability is resolved in Mattermost Server versions 8.1.11, 9.3.3, 9.4.4, or 9.5.2 or later. For more information, visit https://avd.aquasec.com/nvd/2024/cve-2024-29221/.
Read more Communication