Description
Mattermost versions 9.5.x <= 9.5.5 and 9.8.0 fail to properly sanitize the recipients of a webhook event which allows an attacker monitoring webhook events to retrieve the channel IDs of archived or restored channels.
No analysis available yet.
Remediation
Vendor Solution
Update Mattermost to versions 9.9.0, 9.8.1, 9.5.6 or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-38239 | Mattermost versions 9.5.x <= 9.5.5 and 9.8.0 fail to properly sanitize the recipients of a webhook event which allows an attacker monitoring webhook events to retrieve the channel IDs of archived or restored channels. |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
No history.
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-08-02T04:26:16.012Z
Reserved: 2024-07-01T10:22:11.574Z
Link: CVE-2024-39807
Updated: 2024-08-02T04:26:16.012Z
Status : Modified
Published: 2024-07-03T09:15:07.210
Modified: 2026-06-17T07:42:50.530
Link: CVE-2024-39807
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
- NVD-CWE-noinfo
EUVD