Description
Mattermost versions 9.5.x <= 9.5.5 and 9.8.0 fail to sanitize the RemoteClusterFrame payloads before audit logging them which allows a high privileged attacker with access to the audit logs to read message contents.
No analysis available yet.
Remediation
Vendor Solution
Update Mattermost to versions 9.9.0, 9.8.1, 9.5.6 or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-37916 | Mattermost versions 9.5.x <= 9.5.5 and 9.8.0 fail to sanitize the RemoteClusterFrame payloads before audit logging them which allows a high privileged attacker with access to the audit logs to read message contents. |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
No history.
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-08-02T04:26:15.306Z
Reserved: 2024-07-01T10:22:11.603Z
Link: CVE-2024-39353
Updated: 2024-08-02T04:26:15.306Z
Status : Modified
Published: 2024-07-03T09:15:06.617
Modified: 2024-11-21T09:27:31.997
Link: CVE-2024-39353
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD