CVE-2024-37182: Lack of permissions prompting when opening external URLs
Published Jun 14, 2024
·Updated
Mattermost Desktop App versions <=5.7.0 fail to correctly prompt for permission when opening external URLs which allows a remote attacker to force a victim over the Internet to run arbitrary programs on the victim's system via custom URI schemes.
Affected Software
2 affected componentsFixes available
npm/mattermost-desktop<5.8.0
5.8.0
Mattermost Mattermost Desktop<=5.7.0
Remediation
Information
Update Mattermost Desktop App to versions 5.8.0 or higher.
Event History
Jun 14, 2024
CVE Published
via MITRE·08:39 AM
Data Sourced
via MITRE·08:39 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeakness
Advisory Published
via GitHub·09:31 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-37182?
The severity of CVE-2024-37182 is classified as high due to the potential for remote code execution.
2
How do I fix CVE-2024-37182?
To fix CVE-2024-37182, upgrade to Mattermost Desktop App version 5.8.0 or later.
3
What versions are affected by CVE-2024-37182?
CVE-2024-37182 affects Mattermost Desktop App versions 5.7.0 and earlier.
4
Can CVE-2024-37182 allow remote code execution?
Yes, CVE-2024-37182 allows a remote attacker to exploit the application and potentially execute arbitrary code on the victim's system.
5
What attack vectors are associated with CVE-2024-37182?
CVE-2024-37182 can be exploited via custom URI schemes that the application does not properly handle.