CVE-2024-39832Improper Check for Unusual or Exceptional Conditions in Mattermost Mattermost-server

Severity
8.7HIGHNVD
CNA6.8
EPSS
0.3%
top 50.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 1
Latest updateAug 6

Description

Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to properly safeguard an error handling which allows a malicious remote to permanently delete local data by abusing dangerous error handling, when share channels were enabled.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:HExploitability: 2.3 | Impact: 5.8

Affected Packages4 packages

NVDmattermost/mattermost9.5.09.5.7+3
Gogithub.com/mattermost_mattermost-server9.5.0+incompatible9.5.7+incompatible+3
CVEListV5mattermost/mattermost9.5.09.5.6+3

🔴Vulnerability Details

4
OSV
Mattermost allows a remote actor to permanently delete local data by abusing dangerous error handling in github.com/mattermost/mattermost-server2024-08-06
CVEList
Permanently local data deletion by malicious remote2024-08-01
OSV
Mattermost allows a remote actor to permanently delete local data by abusing dangerous error handling2024-08-01
GHSA
Mattermost allows a remote actor to permanently delete local data by abusing dangerous error handling2024-08-01
CVE-2024-39832 — HIGH severity | cvebase