← Back to CVEs
CVE-2024-41144
MEDIUM5.5
Description
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to properly validate synced posts, when shared channels are enabled, which allows a malicious remote to create/update/delete arbitrary posts in arbitrary channels
CVE Details
CVSS v3.1 Score5.5
SeverityMEDIUM
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:L
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredHIGH
User InteractionNONE
Published8/1/2024
Last Modified9/4/2024
Sourcenvd
Honeypot Sightings0
Affected Products
mattermost:mattermost_server
Weaknesses (CWE)
CWE-284
References
https://mattermost.com/security-updates(responsibledisclosure@mattermost.com)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.