Description
Mattermost fails to check if compliance export is enabled when fetching posts of public channels allowing a user that is not a member of the public channel to fetch the posts, which will not be audited in the compliance export.
No analysis available yet.
Remediation
Vendor Solution
Update Mattermost Server to versions 9.4,0, 9.3.1, 9.2.5, 8.1.9 or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0634 | Mattermost fails to check if compliance export is enabled when fetching posts of public channels allowing a user that is not a member of the public channel to fetch the posts, which will not be audited in the compliance export. |
Github GHSA |
GHSA-fx48-xv6q-6gp3 | Mattermost post fetching without auditing in compliance export |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
Mon, 12 May 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost
Mattermost mattermost Server |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mattermost
Mattermost mattermost Server |
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-08-07T17:38:09.687Z
Reserved: 2024-02-26T09:14:30.337Z
Link: CVE-2024-1887
Updated: 2024-08-01T18:56:22.552Z
Status : Analyzed
Published: 2024-02-29T08:15:46.437
Modified: 2025-05-12T13:32:55.320
Link: CVE-2024-1887
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA