4.3
CVE-2024-52032
- EPSS 0.3%
- Veröffentlicht 09.11.2024 18:15:15
- Zuletzt bearbeitet 14.11.2024 16:47:21
- Erkennungen
Private channel names leaking when Elasticsearch is enabled
Mattermost versions 10.0.x <= 10.0.0 and 9.11.x <= 9.11.2 fail to properly query ElasticSearch when searching for the channel name in channel switcher which allows an attacker to get private channels names of channels that they are not a member of, when Elasticsearch v8 was enabled.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mattermost ≫ Mattermost Server Version >= 9.11.0 < 9.11.3
Mattermost ≫ Mattermost Server Version 10.0.0 Update -
Mattermost ≫ Mattermost Server Version 10.0.0 Update rc1
Mattermost ≫ Mattermost Server Version 10.0.0 Update rc2
Mattermost ≫ Mattermost Server Version 10.0.0 Update rc3
Mattermost ≫ Mattermost Server Version 10.0.0 Update rc4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.3% | 0.222 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
| responsibledisclosure@mattermost.com | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
https://mattermost.com/security-updates