Mattermost versions 9.5.x <= 9.5.8 fail to properly authorize access to archived channels when viewing archived channels is disabled, which allows an attacker to view posts and files of archived channels via file links.
References
History

Thu, 26 Sep 2024 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost
Mattermost mattermost Server
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
Vendors & Products Mattermost
Mattermost mattermost Server

Thu, 26 Sep 2024 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 26 Sep 2024 08:15:00 +0000

Type Values Removed Values Added
Description Mattermost versions 9.5.x <= 9.5.8 fail to properly authorize access to archived channels when viewing archived channels is disabled, which allows an attacker to view posts and files of archived channels via file links.
Title Unauthorized access on archived channels via file links
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published: 2024-09-26T08:01:48.199Z

Updated: 2024-09-26T13:12:52.240Z

Reserved: 2024-09-23T07:55:36.353Z

Link: CVE-2024-47145

cve-icon Vulnrichment

Updated: 2024-09-26T13:12:49.125Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-26T08:15:06.403

Modified: 2024-09-26T18:42:33.550

Link: CVE-2024-47145

cve-icon Redhat

No data.