CVE Vulnerabilities

CVE-2024-39353

Published: Jul 03, 2024 | Modified: Jul 05, 2024
CVSS 3.x
2.7
LOW
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Mattermost versions 9.5.x <= 9.5.5 and 9.8.0 fail to sanitize the RemoteClusterFrame payloads before audit logging them which allows a high privileged attacker with access to the audit logs to read message contents.

Affected Software

Name Vendor Start Version End Version
Mattermost Mattermost 9.5.0 (including) 9.5.6 (excluding)
Mattermost Mattermost 9.8.0 (including) 9.8.0 (including)

References