CVE-2024-32046
published 2024-04-26CVE-2024-32046: Mattermost versions 9.6.x <= 9.6.0, 9.5.x <= 9.5.2, 9.4.x <= 9.4.4 and 8.1.x <= 8.1.11 fail to remove detailed error messages in API requests even if the…
PriorityP422medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
0.45%
36.9th percentile
Mattermost versions 9.6.x <= 9.6.0, 9.5.x <= 9.5.2, 9.4.x <= 9.4.4 and 8.1.x <= 8.1.11 fail to remove detailed error messages in API requests even if the developer mode is off which allows an attacker to get information about the server such as the full path were files are stored
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | mattermost_mattermost-server | >= 8.1.0 < 8.1.12 | 8.1.12 |
| github.com | mattermost_mattermost-server | >= 8.1.0+incompatible < 8.1.12+incompatible | 8.1.12+incompatible |
| github.com | mattermost_mattermost-server | >= 9.4.0 < 9.4.5 | 9.4.5 |
| github.com | mattermost_mattermost-server | >= 9.4.0+incompatible < 9.4.5+incompatible | 9.4.5+incompatible |
| github.com | mattermost_mattermost-server | >= 9.5.0 < 9.5.3 | 9.5.3 |
| github.com | mattermost_mattermost-server | >= 9.5.0+incompatible < 9.5.3+incompatible | 9.5.3+incompatible |
| github.com | mattermost_mattermost-server | >= 9.6.0-rc1 < 9.6.1 | 9.6.1 |
| github.com | mattermost_mattermost-server | >= 9.6.0-rc1+incompatible < 9.6.1+incompatible | 9.6.1+incompatible |
| mattermost | mattermost | — | — |
| mattermost | mattermost | 8.1.0 – 8.1.11 | — |
| mattermost | mattermost | 9.4.0 – 9.4.4 | — |
| mattermost | mattermost | 9.5.0 – 9.5.2 | — |
| mattermost | mattermost_server | >= 8.1.0 < 8.1.12 | 8.1.12 |
| mattermost | mattermost_server | >= 9.4.0 < 9.4.5 | 9.4.5 |
| mattermost | mattermost_server | >= 9.5.0 < 9.5.3 | 9.5.3 |
| mattermost | mattermost_server | >= 9.6.0 < 9.6.1 | 9.6.1 |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Mattermost's detailed error messages reveal the full file path in github.com/mattermost/mattermost-server
osv·2024-06-05
CVE-2024-32046 Mattermost's detailed error messages reveal the full file path in github.com/mattermost/mattermost-server
Mattermost's detailed error messages reveal the full file path in github.com/mattermost/mattermost-server
Mattermost's detailed error messages reveal the full file path in github.com/mattermost/mattermost-server
GHSA
Mattermost's detailed error messages reveal the full file path
ghsa·2024-04-26
CVE-2024-32046 [MEDIUM] CWE-200 Mattermost's detailed error messages reveal the full file path
Mattermost's detailed error messages reveal the full file path
Mattermost versions 9.6.x <= 9.6.0, 9.5.x <= 9.5.2, 9.4.x <= 9.4.4 and 8.1.x <= 8.1.11 fail to remove detailed error messages in API requests even if the developer mode is off which allows an attacker to get information about the server such as the full path were files are stored
OSV
Mattermost's detailed error messages reveal the full file path
osv·2024-04-26
CVE-2024-32046 [MEDIUM] Mattermost's detailed error messages reveal the full file path
Mattermost's detailed error messages reveal the full file path
Mattermost versions 9.6.x <= 9.6.0, 9.5.x <= 9.5.2, 9.4.x <= 9.4.4 and 8.1.x <= 8.1.11 fail to remove detailed error messages in API requests even if the developer mode is off which allows an attacker to get information about the server such as the full path were files are stored
Red Hat
mattermost: allows an attacker to get information about the server such as the full path were files are stored
vendor_redhat·2024-04-26·CVSS 4.3
CVE-2024-32046 [MEDIUM] CWE-200 mattermost: allows an attacker to get information about the server such as the full path were files are stored
mattermost: allows an attacker to get information about the server such as the full path were files are stored
Mattermost versions 9.6.x <= 9.6.0, 9.5.x <= 9.5.2, 9.4.x <= 9.4.4 and 8.1.x <= 8.1.11 fail to remove detailed error messages in API requests even if the developer mode is off which allows an attacker to get information about the server such as the full path were files are stored
A flaw was found in Mattermost, where it fails to remove detailed error messages in API requests even if the developer mode is off. This flaw allows an attacker to obtain information about the server, such as the full path where files are stored.
Package: rhacm2/acm-grafana-rhel8 (Red Hat Advanced Cluster Management for Kubernetes 2) - Fix deferred
Package: advanced-cluster-security/rhacs-docs-rhel8 (
No detection rules found.
No public exploits indexed.
2024-04-26
Published