Mattermost是美国Mattermost公司的一个开源协作平台。 Mattermost 9.5.x至9.5.5和9.8.0版本存在安全漏洞,该漏洞源于未能正确清理webhook事件的接收者,攻击者可以检索已存档或恢复的频道的ID。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Mattermost | Mattermost | 9.8.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-39830 | 8.1 HIGH | Timing attack during remote cluster token comparison when shared channels are enabled |
| CVE-2024-6428 | 5.3 MEDIUM | Limited DoS due to permitting creating users with user-defined IDs |
| CVE-2024-39361 | 3.1 LOW | Creating posts with user-defined IDs permitted in CreatePost API |
| CVE-2024-36257 | 2.7 LOW | Lack of permission check when updating the profile picture of a remote user (shared channe |
| CVE-2024-39353 | 2.7 LOW | RemoteClusterFrame payloads are audit logged in full |
No comments yet