CVE-2024-2447: Medium severity mattermost vulnerability
Mattermost versions 8.1.x before 8.1.11, 9.3.x before 9.3.3, 9.4.x before 9.4.4, and 9.5.x before 9.5.2 fail to authenticate the source of certain types of post actions, allowing an authenticated attacker to create posts as other users via a crafted post action.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2447?
CVE-2024-2447 is rated as a moderate severity vulnerability due to the potential for authenticated users to impersonate other users.
How do I fix CVE-2024-2447?
To fix CVE-2024-2447, you should upgrade Mattermost Server to version 8.1.11, 9.3.3, 9.4.4, or 9.5.2.
What versions of Mattermost are affected by CVE-2024-2447?
CVE-2024-2447 affects Mattermost versions 8.1.x prior to 8.1.11, 9.3.x prior to 9.3.3, 9.4.x prior to 9.4.4, and 9.5.x prior to 9.5.2.
Can CVE-2024-2447 be exploited remotely?
CVE-2024-2447 requires authentication to exploit, as it involves actions taken by authenticated users.
What type of attack does CVE-2024-2447 enable?
CVE-2024-2447 enables an authenticated attacker to create posts as other users via crafted post actions.