Description
Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to enforce proper access controls for channel and team membership when linking a playbook run to a channel which allows members to link their runs to private channels they were not members of.
No analysis available yet.
Remediation
Vendor Solution
Update Mattermost to versions 9.7.0, 9.5.4, 9.6.2, 8.1.13 or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-34458 | Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to enforce proper access controls for channel and team membership when linking a playbook run to a channel which allows members to link their runs to private channels they were not members of. |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
Tue, 30 Sep 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost mattermost Server
|
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mattermost mattermost Server
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-08-02T02:06:42.837Z
Reserved: 2024-05-23T10:57:59.892Z
Link: CVE-2024-32045
Updated: 2024-08-02T02:06:42.837Z
Status : Analyzed
Published: 2024-05-26T14:15:09.137
Modified: 2025-09-30T15:24:46.110
Link: CVE-2024-32045
No data.
OpenCVE Enrichment
Updated: 2025-07-12T22:00:52Z
EUVD