CVE-2024-32045: Playbook run link to private channel grants channel access
Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to enforce proper access controls for channel and team membership when linking a playbook run to a channel which allows members to link their runs to private channels they were not members of.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-32045?
The severity of CVE-2024-32045 is classified as a high-severity vulnerability.
How do I fix CVE-2024-32045?
To fix CVE-2024-32045, upgrade Mattermost to version 9.5.4 or later, 9.6.2 or later, or 8.1.13 or later.
What versions of Mattermost are affected by CVE-2024-32045?
CVE-2024-32045 affects Mattermost versions 9.5.x up to 9.5.3, 9.6.x up to 9.6.1, and 8.1.x up to 8.1.12.
What type of vulnerability is CVE-2024-32045?
CVE-2024-32045 is an access control vulnerability that allows users to link playbook runs to private channels without proper permissions.
What are the potential impacts of CVE-2024-32045?
The potential impacts of CVE-2024-32045 include unauthorized access to private channel content and loss of data confidentiality.