BIT-mattermost-2024-1942

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/mattermost/BIT-mattermost-2024-1942.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-mattermost-2024-1942
Aliases
Published
2024-12-16T07:16:27.079Z
Modified
2024-12-16T13:41:51.947357Z
Summary
[none]
Details

Mattermost versions 8.1.x before 8.1.9, 9.2.x before 9.2.5, and 9.3.0 fail to sanitize the metadata on posts containing permalinks under specific conditions, which allows an authenticated attacker to access the contents of individual posts in channels they are not a member of.

Database specific
{
    "cpes": [
        "cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*",
        "cpe:2.3:a:mattermost:mattermost_server:9.3.0:*:*:*:*:*:*:*"
    ],
    "severity": "Medium"
}
References

Affected packages

Bitnami / mattermost

Package

Name
mattermost
Purl
pkg:bitnami/mattermost

Severity

  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
8.1.0
Fixed
8.1.9
Introduced
9.2.0
Fixed
9.2.5
Type
SEMVER
Events
Introduced
9.3.0
Last affected
9.3.0