CVE-2024-42406

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Sep 26, 2024
Updated: Oct 1, 2024
CWE ID 284

Summary

CVE-2024-42406 is a vulnerability affecting Mattermost versions 9.11.x up to 9.11.0, 9.10.x up to 9.10.1, 9.9.x up to 9.9.2, and 9.5.x up to 9.5.8. When archived channels are disabled, these versions fail to authorize proper requests, allowing attackers to retrieve information about archived channels. This includes flagged or unread posts and files, posing a risk to sensitive data.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Mattermost Server

Affected Vendors

  • Mattermost, Inc.