CVE-2024-47145

Mattermost versions 9.5.x <= 9.5.8 fail to properly authorize access to archived channels when viewing archived channels is disabled, which allows an attacker to view posts and files of archived channels via file links.
References
Link Resource
https://mattermost.com/security-updates Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-09-26 08:15

Updated : 2024-09-26 18:42


NVD link : CVE-2024-47145

Mitre link : CVE-2024-47145

CVE.ORG link : CVE-2024-47145


JSON object : View

Products Affected

mattermost

  • mattermost_server
CWE
CWE-284

Improper Access Control

NVD-CWE-noinfo