Mattermost versions 9.5.x <= 9.5.8 fail to properly authorize access to archived channels when viewing archived channels is disabled, which allows an attacker to view posts and files of archived channels via file links.
References
Link | Resource |
---|---|
https://mattermost.com/security-updates | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2024-09-26 08:15
Updated : 2024-09-26 18:42
NVD link : CVE-2024-47145
Mitre link : CVE-2024-47145
CVE.ORG link : CVE-2024-47145
JSON object : View
Products Affected
mattermost
- mattermost_server
CWE