Mattermost versions 9.5.x <= 9.5.8 fail to include the metadata endpoints of Oracle Cloud and Alibaba in the SSRF denylist, which allows an attacker to possibly cause an SSRF if Mattermost was deployed in Oracle Cloud or Alibaba.
References
History

Thu, 26 Sep 2024 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost
Mattermost mattermost Server
CPEs cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
Vendors & Products Mattermost
Mattermost mattermost Server

Thu, 26 Sep 2024 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 26 Sep 2024 08:15:00 +0000

Type Values Removed Values Added
Description Mattermost versions 9.5.x <= 9.5.8 fail to include the metadata endpoints of Oracle Cloud and Alibaba in the SSRF denylist, which allows an attacker to possibly cause an SSRF if Mattermost was deployed in Oracle Cloud or Alibaba.
Title Weak SSRF Filtering
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published: 2024-09-26T08:03:41.827Z

Updated: 2024-09-26T13:11:54.474Z

Reserved: 2024-09-23T07:55:36.370Z

Link: CVE-2024-45843

cve-icon Vulnrichment

Updated: 2024-09-26T13:11:50.749Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-26T08:15:06.020

Modified: 2024-09-26T18:42:26.697

Link: CVE-2024-45843

cve-icon Redhat

No data.