CVE-2024-34152: Playbook Run Metadata leak to Guest

Published May 26, 2024
·
Updated

Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to perform proper access control which allows a guest to get the metadata of a public playbook run that linked to the channel they are guest via sending an RHSRuns GraphQL query request to the server

Affected Software

4 affected components
Mattermost Mattermost<=9.5.3, <=9.6.1, <=8.1.12
Mattermost Mattermost Server>=8.1.0<8.1.13
Mattermost Mattermost Server>=9.5.0<9.5.4
Mattermost Mattermost Server>=9.6.0<9.6.2

Remediation

Information

Update Mattermost to versions 9.7.0, 9.5.4, 9.6.2, 8.1.13 or higher.

Event History

May 26, 2024
CVE Published
via MITRE·01:28 PM
Data Sourced
via MITRE·01:28 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2024-34152?

The severity of CVE-2024-34152 is considered medium due to improper access control allowing unauthorized access to metadata.

2

How do I fix CVE-2024-34152?

To fix CVE-2024-34152, upgrade Mattermost to version 9.5.4, 9.6.2, or 8.1.13 or later to ensure proper access controls are implemented.

3

Who is affected by CVE-2024-34152?

CVE-2024-34152 affects Mattermost versions 9.5.x up to 9.5.3, 9.6.x up to 9.6.1, and 8.1.x up to 8.1.12.

4

What type of vulnerability is CVE-2024-34152?

CVE-2024-34152 is an access control vulnerability allowing guests to retrieve sensitive metadata related to public playbook runs.

5

What can attackers do with CVE-2024-34152?

With CVE-2024-34152, attackers can send RHSRuns GraphQL queries to access sensitive metadata that they should not have permission to view.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203