CVE-2024-39832 — Improper Check for Unusual or Exceptional Conditions in Mattermost Mattermost-server
Severity
8.7HIGHNVD
CNA6.8
EPSS
0.3%
top 50.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 1
Latest updateAug 6
Description
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to properly safeguard an error handling which allows a malicious remote to permanently delete local data by abusing dangerous error handling, when share channels were enabled.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:HExploitability: 2.3 | Impact: 5.8
Affected Packages4 packages
🔴Vulnerability Details
4OSV▶
Mattermost allows a remote actor to permanently delete local data by abusing dangerous error handling in github.com/mattermost/mattermost-server↗2024-08-06
OSV▶
Mattermost allows a remote actor to permanently delete local data by abusing dangerous error handling↗2024-08-01
GHSA▶
Mattermost allows a remote actor to permanently delete local data by abusing dangerous error handling↗2024-08-01