CVE-2024-42406: Unauthorized access on archived channels
Mattermost versions 9.11.x <= 9.11.0, 9.10.x <= 9.10.1, 9.9.x <= 9.9.2 and 9.5.x <= 9.5.8 fail to properly authorize requests when viewing archived channels is disabled, which allows an attacker to retrieve post and file information about archived channels. Examples are flagged or unread posts as well as files.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-42406?
CVE-2024-42406 has a high severity rating due to the potential unauthorized access to sensitive information.
How do I fix CVE-2024-42406?
To fix CVE-2024-42406, upgrade Mattermost Server to version 9.11.1 or higher, or the appropriate patched version for earlier releases.
What versions are affected by CVE-2024-42406?
CVE-2024-42406 affects Mattermost versions 9.11.x up to 9.11.0, 9.10.x up to 9.10.1, 9.9.x up to 9.9.2, and 9.5.x up to 9.5.8.
What type of attack does CVE-2024-42406 enable?
CVE-2024-42406 enables an attacker to retrieve post and file information from archived channels without proper authorization.
Is there a workaround for CVE-2024-42406?
There are no specific workarounds for CVE-2024-42406; the recommended action is to apply the security updates.