CVE-2024-36241: /playbook add slash command allows viewing arbitrary post contents
Published May 26, 2024
·Updated
Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to enforce proper access controls which allows user to view arbitrary post contents via the /playbook add slash command
Affected Software
4 affected components
Mattermost Mattermost>=9.5.0<9.5.4, >=9.6.0<9.6.2, >=8.1.0<8.1.13
Mattermost Mattermost Server>=8.1.0<8.1.13
Mattermost Mattermost Server>=9.5.0<9.5.4
Mattermost Mattermost Server>=9.6.0<9.6.2
Remediation
Information
Update Mattermost to versions 9.7.0, 9.5.4, 9.6.2, 8.1.13 or higher.
Event History
May 26, 2024
CVE Published
via MITRE·01:32 PM
Data Sourced
via MITRE·01:32 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-36241?
CVE-2024-36241 is rated as a medium severity vulnerability due to improper access controls.
2
How do I fix CVE-2024-36241?
To fix CVE-2024-36241, upgrade Mattermost to versions 9.5.4, 9.6.2, or 8.1.13 or later.
3
What versions of Mattermost are affected by CVE-2024-36241?
CVE-2024-36241 affects Mattermost versions 9.5.x up to 9.5.3, 9.6.x up to 9.6.1, and 8.1.x up to 8.1.12.
4
What type of vulnerability is CVE-2024-36241?
CVE-2024-36241 is a vulnerability related to improper access controls allowing users to view unauthorized post contents.
5
Can CVE-2024-36241 be exploited remotely?
Yes, CVE-2024-36241 can potentially be exploited remotely if the affected Mattermost versions are accessible to unauthorized users.