CVE-2024-34152: Playbook Run Metadata leak to Guest
Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to perform proper access control which allows a guest to get the metadata of a public playbook run that linked to the channel they are guest via sending an RHSRuns GraphQL query request to the server
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-34152?
The severity of CVE-2024-34152 is considered medium due to improper access control allowing unauthorized access to metadata.
How do I fix CVE-2024-34152?
To fix CVE-2024-34152, upgrade Mattermost to version 9.5.4, 9.6.2, or 8.1.13 or later to ensure proper access controls are implemented.
Who is affected by CVE-2024-34152?
CVE-2024-34152 affects Mattermost versions 9.5.x up to 9.5.3, 9.6.x up to 9.6.1, and 8.1.x up to 8.1.12.
What type of vulnerability is CVE-2024-34152?
CVE-2024-34152 is an access control vulnerability allowing guests to retrieve sensitive metadata related to public playbook runs.
What can attackers do with CVE-2024-34152?
With CVE-2024-34152, attackers can send RHSRuns GraphQL queries to access sensitive metadata that they should not have permission to view.