CVE-2024-1942: Medium severity mattermost vulnerability
Mattermost versions 8.1.x before 8.1.9, 9.2.x before 9.2.5, and 9.3.0 fail to sanitize the metadata on posts containing permalinks under specific conditions, which allows an authenticated attacker to access the contents of individual posts in channels they are not a member of.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1942?
CVE-2024-1942 is classified as a medium severity vulnerability due to its potential impact on unauthorized information access.
How do I fix CVE-2024-1942?
To fix CVE-2024-1942, upgrade Mattermost to versions 8.1.9, 9.2.5, or 9.3.1 or later.
What versions of Mattermost are affected by CVE-2024-1942?
CVE-2024-1942 affects Mattermost versions 8.1.x prior to 8.1.9, 9.2.x prior to 9.2.5, and 9.3.0.
Is there a workaround for CVE-2024-1942?
There are no known workarounds for CVE-2024-1942; upgrading to a patched version is advised.
What type of attack does CVE-2024-1942 allow?
CVE-2024-1942 allows an authenticated attacker to access the contents of individual posts in channels they are not members of.