Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-29215


Mattermost versions 9.5.x <= 9.5.3, 9.7.x <= 9.7.1, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to enforce proper access control which allows a user to run a slash command in a channel they are not a member of via linking a playbook run to that channel and running a slash command as a playbook task command.


Published

2024-05-26T14:15:08.627

Last Modified

2025-07-08T18:02:30.957

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 4.3 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-284

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application mattermost mattermost_server < 8.1.13 Yes
Application mattermost mattermost_server < 9.5.4 Yes
Application mattermost mattermost_server < 9.6.2 Yes
Application mattermost mattermost_server < 9.7.2 Yes

References