CVE-2024-1952: Infoleak
Published Feb 29, 2024
·Updated
Mattermost version 8.1.x before 8.1.9 fails to sanitize data associated with permalinks when a plugin updates an ephemeral post, allowing an authenticated attacker who can control the ephemeral post update to access individual posts' contents in channels they are not a member of.
Affected Software
2 affected componentsFixes available
go/github.com/mattermost/mattermost/server/v8>=9.0.0<9.4.0
9.4.0
Mattermost Mattermost Server>=8.1.0<8.1.9
Remediation
Information
Update Mattermost Server to versions 9.4, 8.1.9 or higher.
Event History
Feb 29, 2024
CVE Published
via MITRE·10:42 AM
Data Sourced
via MITRE·10:42 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeakness
Advisory Published
via GitHub·12:31 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-1952?
CVE-2024-1952 has a medium severity, as it allows authenticated attackers to access sensitive post contents.
2
How do I fix CVE-2024-1952?
To fix CVE-2024-1952, update your Mattermost Server to version 8.1.9 or later.
3
Which versions of Mattermost are affected by CVE-2024-1952?
CVE-2024-1952 affects Mattermost Server versions 8.1.0 to 8.1.8.
4
Who can exploit CVE-2024-1952?
CVE-2024-1952 can be exploited by authenticated attackers who control the update of ephemeral posts.
5
What type of vulnerability is CVE-2024-1952?
CVE-2024-1952 is a data exposure vulnerability due to improper data sanitization.