Mattermost versions 9.5.x <= 9.5.5 and 9.8.0 fail to properly sanitize the recipients of a webhook event which allows an attacker monitoring webhook events to retrieve the channel IDs of archived or restored channels.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-38239 Mattermost versions 9.5.x <= 9.5.5 and 9.8.0 fail to properly sanitize the recipients of a webhook event which allows an attacker monitoring webhook events to retrieve the channel IDs of archived or restored channels.
Fixes

Solution

Update Mattermost to versions 9.9.0, 9.8.1, 9.5.6 or higher.


Workaround

No workaround given by the vendor.

References
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2024-08-02T04:26:16.012Z

Reserved: 2024-07-01T10:22:11.574Z

Link: CVE-2024-39807

cve-icon Vulnrichment

Updated: 2024-08-02T04:26:16.012Z

cve-icon NVD

Status : Modified

Published: 2024-07-03T09:15:07.210

Modified: 2024-11-21T09:28:22.227

Link: CVE-2024-39807

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.