Description
Mattermost versions 9.5.x <= 9.5.5 and 9.8.0 fail to properly sanitize the recipients of a webhook event which allows an attacker monitoring webhook events to retrieve the channel IDs of archived or restored channels.
No analysis available yet.
Remediation
Vendor Solution
Update Mattermost to versions 9.9.0, 9.8.1, 9.5.6 or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-38239 | Mattermost versions 9.5.x <= 9.5.5 and 9.8.0 fail to properly sanitize the recipients of a webhook event which allows an attacker monitoring webhook events to retrieve the channel IDs of archived or restored channels. |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
No history.
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-08-02T04:26:16.012Z
Reserved: 2024-07-01T10:22:11.574Z
Link: CVE-2024-39807
Updated: 2024-08-02T04:26:16.012Z
Status : Modified
Published: 2024-07-03T09:15:07.210
Modified: 2024-11-21T09:28:22.227
Link: CVE-2024-39807
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD