CVE Vulnerabilities

CVE-2024-47145

Published: Sep 26, 2024 | Modified: Sep 26, 2024
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Mattermost versions 9.5.x <= 9.5.8 fail to properly authorize access to archived channels when viewing archived channels is disabled, which allows an attacker to view posts and files of archived channels via file links.

Affected Software

Name Vendor Start Version End Version
Mattermost_server Mattermost 9.5.0 (including) 9.5.9 (excluding)

References