Description
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.0, 9.8.x <= 9.8.2 fail to enforce permissions which allows a guest user with read access to upload files to a channel.
Published: 2024-08-22
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Update Mattermost to versions 9.11.0, 9.9.2, 9.5.8, 9.10.1, 9.8.3 or higher.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-2464 Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.0, 9.8.x <= 9.8.2 fail to enforce permissions which allows a guest user with read access to upload files to a channel.
Github GHSA Github GHSA GHSA-2jhx-w3vc-w59g Mattermost allows guest user with read access to upload files to a channel
History

Wed, 16 Oct 2024 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost
Mattermost mattermost Server
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
cpe:2.3:a:mattermost:mattermost_server:9.10.0:*:*:*:*:*:*:*
Vendors & Products Mattermost
Mattermost mattermost Server

Thu, 22 Aug 2024 23:30:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Thu, 22 Aug 2024 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 22 Aug 2024 15:30:00 +0000

Type Values Removed Values Added
Description Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.0, 9.8.x <= 9.8.2 fail to enforce permissions which allows a guest user with read access to upload files to a channel.
Title Unauthorized channel file upload
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Mattermost Mattermost Server
cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2024-08-22T16:06:25.703Z

Reserved: 2024-08-16T17:27:00.321Z

Link: CVE-2024-43780

cve-icon Vulnrichment

Updated: 2024-08-22T16:06:17.238Z

cve-icon NVD

Status : Analyzed

Published: 2024-08-22T16:15:09.897

Modified: 2024-10-16T20:07:50.637

Link: CVE-2024-43780

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-08-22T16:15:09Z

Links: CVE-2024-43780 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses