CVE-2024-42000
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Nov 9, 2024
Updated: Nov 14, 2024
CWE ID 863
Summary
CVE-2024-42000 is a vulnerability affecting Mattermost versions 9.10.x up to 9.10.2, 9.11.x up to 9.11.1, 9.5.x up to 9.5.9, and 10.0.x up to 10.0.0. These versions fail to properly authorize requests to the /api/v4/channels endpoint. Consequently, a User or System Manager with "Read Groups" permission but no channel access can retrieve details about private channels they were not a member of by sending a request to this endpoint. This vulnerability poses a significant risk for unauthorized access to private channel information.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Mattermost Server
Affected Vendors
- Mattermost, Inc.