CVE-2024-50052
published 2024-10-29CVE-2024-50052: Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 fail to check that the origin of the message in an integration action matches with the…
PriorityP424medium4.3CVSS 3.1
AVNACLPRLUINSUCNILAN
EPSS
0.27%
19.0th percentile
Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 fail to check that the origin of the message in an integration action matches with the original post metadata which allows an authenticated user to delete an arbitrary post.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | mattermost_mattermost_server_v8 | >= 0 < 8.0.0-20240926115259-20ed58906adc | 8.0.0-20240926115259-20ed58906adc |
| mattermost | mattermost | 9.10.0 – 9.10.2 | — |
| mattermost | mattermost | 9.11.0 – 9.11.1 | — |
| mattermost | mattermost | 9.5.0 – 9.5.9 | — |
| mattermost | mattermost_server | >= 9.10.0 < 9.10.3 | 9.10.3 |
| mattermost | mattermost_server | >= 9.11.0 < 9.11.2 | 9.11.2 |
| mattermost | mattermost_server | >= 9.5.0 < 9.5.10 | 9.5.10 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server
osv·2024-11-04
CVE-2024-50052 Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server
Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server
Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server
GHSA
Mattermost server allows authenticated user to delete arbitrary post
ghsa·2024-10-29
CVE-2024-50052 [MEDIUM] CWE-862 Mattermost server allows authenticated user to delete arbitrary post
Mattermost server allows authenticated user to delete arbitrary post
Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 fail to check that the origin of the message in an integration action matches with the original post metadata which allows an authenticated user to delete an arbitrary post.
OSV
Mattermost server allows authenticated user to delete arbitrary post
osv·2024-10-29
CVE-2024-50052 [MEDIUM] Mattermost server allows authenticated user to delete arbitrary post
Mattermost server allows authenticated user to delete arbitrary post
Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 fail to check that the origin of the message in an integration action matches with the original post metadata which allows an authenticated user to delete an arbitrary post.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-10-29
Published