CVE-2024-5272: Run Details leak to guest via webhook event "custom_playbooks_playbook_run_updated"
Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to restrict the audience of the "customplaybooksplaybookrunupdated" webhook event, which allows a guest on a channel with a playbook run linked to see all the details of the playbook run when the run is marked by finished.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 9.7.0 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 9.5.4 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 9.6.2 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 8.1.13
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5272?
CVE-2024-5272 is rated as a high-severity vulnerability due to unauthorized access to sensitive playbook run details by guests.
How do I fix CVE-2024-5272?
To fix CVE-2024-5272, upgrade Mattermost to versions 9.5.4, 9.6.2, or later versions beyond 8.1.12.
What are the affected versions for CVE-2024-5272?
CVE-2024-5272 affects Mattermost versions 9.5.x up to 9.5.3, 9.6.x up to 9.6.1, and 8.1.x up to 8.1.12.
What is the impact of CVE-2024-5272?
The impact of CVE-2024-5272 allows guests in a channel to access all details of a linked playbook run, breaching confidentiality.
Is there a workaround for CVE-2024-5272?
There are no known workarounds for CVE-2024-5272, and upgrading to a patched version is the recommended solution.