First published: Thu Sep 26 2024(Updated: )
Mattermost versions 9.10.x <= 9.10.1, 9.9.x <= 9.9.2, 9.5.x <= 9.5.8 fail to limit access to channels files that have not been linked to a post which allows an attacker to view them in channels that they are a member of.
Credit: responsibledisclosure@mattermost.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mattermost | <=9.10.1<=9.9.2<=9.5.8 |
Update Mattermost to versions 9.11.0, 9.10.2, 9.9.3, 9.5.9 or higher.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-9155 is classified as a high severity vulnerability due to unauthorized access to sensitive channel files.
To fix CVE-2024-9155, upgrade your Mattermost installation to version 9.10.2 or higher, 9.9.3 or higher, or 9.5.9 or higher.
Mattermost versions 9.10.x up to 9.10.1, 9.9.x up to 9.9.2, and 9.5.x up to 9.5.8 are affected by CVE-2024-9155.
CVE-2024-9155 allows attackers to view channel files that have not been linked to any posts within channels they belong to.
Yes, user roles in Mattermost may impact the extent of access to vulnerable files as the issue is related to access controls within the channel.