CVE-2024-42406
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published Sep 26, 2024
Updated: Oct 1, 2024
CWE ID 284
Summary
CVE-2024-42406 is a vulnerability affecting Mattermost versions 9.11.x up to 9.11.0, 9.10.x up to 9.10.1, 9.9.x up to 9.9.2, and 9.5.x up to 9.5.8. When archived channels are disabled, these versions fail to authorize proper requests, allowing attackers to retrieve information about archived channels. This includes flagged or unread posts and files, posing a risk to sensitive data.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Mattermost Server
Affected Vendors
- Mattermost, Inc.