Description
Mattermost Desktop App versions <=5.7.0 fail to correctly prompt for permission when opening external URLs which allows a remote attacker to force a victim over the Internet to run arbitrary programs on the victim's system via custom URI schemes.
No analysis available yet.
Remediation
Vendor Solution
Update Mattermost Desktop App to versions 5.8.0 or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2077 | Mattermost Desktop App versions <=5.7.0 fail to correctly prompt for permission when opening external URLs which allows a remote attacker to force a victim over the Internet to run arbitrary programs on the victim's system via custom URI schemes. |
Github GHSA |
GHSA-hvxg-77mg-vrvp | Mattermost Desktop App Remote Code Execution |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
Wed, 07 Aug 2024 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost
Mattermost mattermost Desktop |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:mattermost:mattermost_desktop:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mattermost
Mattermost mattermost Desktop |
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-08-02T03:50:55.403Z
Reserved: 2024-06-14T08:22:33.365Z
Link: CVE-2024-37182
Updated: 2024-08-02T03:50:55.403Z
Status : Modified
Published: 2024-06-14T09:15:10.013
Modified: 2024-11-21T09:23:22.580
Link: CVE-2024-37182
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA