CVE-2024-1949Sensitive Information Exposure in Mattermost Mattermost-server

Severity
2.6LOWNVD
EPSS
0.3%
top 49.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 29
Latest updateJun 28

Description

A race condition in Mattermost versions 8.1.x before 8.1.9, and 9.4.x before 9.4.2 allows an authenticated attacker to gain unauthorized access to individual posts' contents via carefully timed post creation while another user deletes posts.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:NExploitability: 1.2 | Impact: 1.4

Affected Packages4 packages

NVDmattermost/mattermost_server8.1.08.1.9+1
Gogithub.com/mattermost_mattermost-server9.0.0+incompatible9.4.2+incompatible
CVEListV5mattermost/mattermost8.1.08.1.8+1

🔴Vulnerability Details

4
OSV
Mattermost race condition in github.com/mattermost/mattermost-server2024-06-28
CVEList
CVE-2024-1949: A race condition in Mattermost versions 82024-02-29
OSV
Mattermost race condition2024-02-29
GHSA
Mattermost race condition2024-02-29
CVE-2024-1949 — Sensitive Information Exposure | cvebase