CVE-2024-43813: IDOR when marking read a user's channel
Mattermost versions 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 fail to enforce proper access controls which allows any authenticated user, including guests, to mark any channel inside any team as read for any user.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-43813?
CVE-2024-43813 has a severity rating that reflects significant risks due to insufficient access control vulnerabilities.
How do I fix CVE-2024-43813?
To fix CVE-2024-43813, upgrade Mattermost to version 9.5.8 or higher, or to version 9.10.1 or higher.
Who is affected by CVE-2024-43813?
Any Mattermost deployment running versions 9.5.x up to 9.5.7 or 9.10.x up to 9.10.0 is affected by CVE-2024-43813.
What are the implications of CVE-2024-43813 for users?
Users with authenticated access, including guests, can mark any channel as read for any user, potentially leading to privacy concerns.
Is CVE-2024-43813 a remote vulnerability?
CVE-2024-43813 is not classified as a remote vulnerability since it requires authenticated access to exploit.