CVE-2024-52032: Private channel names leaking when Elasticsearch is enabled
Mattermost versions 10.0.x <= 10.0.0 and 9.11.x <= 9.11.2 fail to properly query ElasticSearch when searching for the channel name in channel switcher which allows an attacker to get private channels names of channels that they are not a member of, when Elasticsearch v8 was enabled.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-52032?
CVE-2024-52032 has been classified as a medium severity vulnerability.
How does CVE-2024-52032 affect Mattermost?
CVE-2024-52032 allows attackers to obtain the names of private channels they do not belong to when Elasticsearch v8 is enabled.
How do I fix CVE-2024-52032?
To fix CVE-2024-52032, upgrade Mattermost to a version beyond 10.0.0 or 9.11.2.
Which versions of Mattermost are affected by CVE-2024-52032?
Mattermost versions 10.0.0 and 9.11.2, along with any versions in the 9.11.x series up to 9.11.2, are affected by CVE-2024-52032.
Is Elasticsearch required to exploit CVE-2024-52032?
Yes, Elasticsearch v8 must be enabled for CVE-2024-52032 to be exploited.