← Back

CVE-2024-47145

nvd nist
Published: Sep 26, 2024Modified: Sep 26, 2024

JSON object

Loading...
4.3
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Exploitability: 2.8 / Impact: 1.4
Source: NVD

Description

Mattermost versions 9.5.x <= 9.5.8 fail to properly authorize access to archived channels when viewing archived channels is disabled, which allows an attacker to view posts and files of archived channels via file links.

Affected (1)

1 product
Mattermost Server
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 9.5.0 to 9.5.9

References (1)

Source: responsibledisclosure@mattermost.com
Vendor Advisory

Timeline

No history available yet.