Description
Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to restrict the audience of the "custom_playbooks_playbook_run_updated" webhook event, which allows a guest on a channel with a playbook run linked to see all the details of the playbook run when the run is marked by finished.
No analysis available yet.
Remediation
Vendor Solution
Update Mattermost to versions 9.7.0, 9.5.4, 9.6.2, 8.1.13 or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-46509 | Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to restrict the audience of the "custom_playbooks_playbook_run_updated" webhook event, which allows a guest on a channel with a playbook run linked to see all the details of the playbook run when the run is marked by finished. |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
Tue, 30 Sep 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost mattermost Server
|
|
| CPEs | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mattermost mattermost Server
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-08-01T21:11:12.451Z
Reserved: 2024-05-23T14:50:39.877Z
Link: CVE-2024-5272
Updated: 2024-08-01T21:11:12.451Z
Status : Analyzed
Published: 2024-05-26T14:15:10.537
Modified: 2025-09-30T15:48:21.680
Link: CVE-2024-5272
No data.
OpenCVE Enrichment
Updated: 2025-07-12T22:01:08Z
Weaknesses
EUVD