Mattermost是美国Mattermost公司的一个开源协作平台。 Mattermost 9.5.x至9.5.5版本和9.8.0版本存在安全漏洞,该漏洞源于未能在审计日志记录之前清理有效负载,允许具有审计日志访问权限的高权限攻击者读取消息内容。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Mattermost | Mattermost | 9.8.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-39830 | 8.1 HIGH | Timing attack during remote cluster token comparison when shared channels are enabled |
| CVE-2024-6428 | 5.3 MEDIUM | Limited DoS due to permitting creating users with user-defined IDs |
| CVE-2024-39807 | 3.1 LOW | Channel IDs of archived/restored channels leaked via webhook events |
| CVE-2024-39361 | 3.1 LOW | Creating posts with user-defined IDs permitted in CreatePost API |
| CVE-2024-36257 | 2.7 LOW | Lack of permission check when updating the profile picture of a remote user (shared channe |
No comments yet