Description
Mattermost fails to properly restrict the access of files attached to posts in an archived channel, resulting in members being able to access files of archived channels even if the “Allow users to view archived channels” option is disabled.
No analysis available yet.
Remediation
Vendor Solution
Update Mattermost Server to versions 9.5.0, 9.4.2, 8.1.9 or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0766 | Mattermost fails to properly restrict the access of files attached to posts in an archived channel, resulting in members being able to access files of archived channels even if the “Allow users to view archived channels” option is disabled. |
Github GHSA |
GHSA-xgxj-j98c-59rv | Mattermost fails to properly restrict the access of files attached to posts |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
Mon, 12 May 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost
Mattermost mattermost Server |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mattermost
Mattermost mattermost Server |
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-08-01T23:06:24.721Z
Reserved: 2024-02-26T08:14:42.978Z
Link: CVE-2024-23488
Updated: 2024-08-01T23:06:24.721Z
Status : Analyzed
Published: 2024-02-29T08:15:47.110
Modified: 2025-05-12T13:34:26.177
Link: CVE-2024-23488
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA