cbcvebase.
CVE-2024-42000
published 2024-11-09

CVE-2024-42000: Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 and 10.0.x <= 10.0.0 fail to properly authorize the requests to /api/v4/channels which…

medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 and 10.0.x <= 10.0.0 fail to properly authorize the requests to /api/v4/channels which allows a User or System Manager, with "Read Groups" permission but with no access for channels to retrieve details about private channels that they were not a member of by sending a request to /api/v4/channels.

Affected

8 ranges
VendorProductVersion rangeFixed in
mattermostmattermost
mattermostmattermost9.10.0 – 9.10.2
mattermostmattermost9.11.0 – 9.11.1
mattermostmattermost9.5.0 – 9.5.9
mattermostmattermost_server
mattermostmattermost_server>= 9.10.0 < 9.10.39.10.3
mattermostmattermost_server>= 9.11.0 < 9.11.29.11.2
mattermostmattermost_server>= 9.5.0 < 9.5.109.5.10