CVE-2024-43780: Unauthorized channel file upload
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.0, 9.8.x <= 9.8.2 fail to enforce permissions which allows a guest user with read access to upload files to a channel.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-43780?
CVE-2024-43780 is considered a moderate severity vulnerability due to improper permission enforcement allowing unauthorized file uploads.
How do I fix CVE-2024-43780?
To fix CVE-2024-43780, update your Mattermost installation to versions 9.8.3, 9.9.2, 9.10.1, or 9.5.8.
Which versions are affected by CVE-2024-43780?
CVE-2024-43780 affects Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.0, and 9.8.x <= 9.8.2.
What are the consequences of CVE-2024-43780?
The consequences of CVE-2024-43780 include the potential for guest users to upload files to channels, which could lead to data leakage or malware distribution.
Can I check if my Mattermost installation is vulnerable to CVE-2024-43780?
Yes, if your Mattermost version is below 9.8.3, 9.9.2, 9.10.1, or 9.5.8, it is vulnerable to CVE-2024-43780.