Mattermost versions 9.6.x <= 9.6.0, 9.5.x <= 9.5.2, 9.4.x <= 9.4.4 and 8.1.x <= 8.1.11 fail to remove detailed error messages in API requests even if the developer mode is off which allows an attacker to get information about the server such as the full path were files are stored
                
            References
                    | Link | Resource | 
|---|---|
| https://mattermost.com/security-updates | Vendor Advisory | 
| https://mattermost.com/security-updates | Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    12 May 2025, 13:39
| Type | Values Removed | Values Added | 
|---|---|---|
| CPE | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* | |
| References | () https://mattermost.com/security-updates - Vendor Advisory | |
| First Time | Mattermost mattermost Server Mattermost | |
| CWE | CWE-209 | 
Information
                Published : 2024-04-26 09:15
Updated : 2025-05-12 13:39
NVD link : CVE-2024-32046
Mitre link : CVE-2024-32046
CVE.ORG link : CVE-2024-32046
JSON object : View
Products Affected
                mattermost
- mattermost_server
