CVE-2024-39807: Channel IDs of archived/restored channels leaked via webhook events
Mattermost versions 9.5.x <= 9.5.5 and 9.8.0 fail to properly sanitize the recipients of a webhook event which allows an attacker monitoring webhook events to retrieve the channel IDs of archived or restored channels.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39807?
CVE-2024-39807 has a medium severity rating due to the potential exposure of channel IDs in archived or restored channels.
How do I fix CVE-2024-39807?
To fix CVE-2024-39807, upgrade Mattermost to version 9.5.6 or later, or to version 9.8.1 or later.
What versions of Mattermost are affected by CVE-2024-39807?
Mattermost versions 9.5.0 to 9.5.5 and 9.8.0 are affected by CVE-2024-39807.
What type of attack is associated with CVE-2024-39807?
CVE-2024-39807 is associated with an information disclosure attack that allows an attacker to monitor webhook events.
Can CVE-2024-39807 affect my organization’s data?
Yes, CVE-2024-39807 can potentially expose sensitive channel IDs, which may compromise the confidentiality of your organization’s data.