Mattermost versions 9.5.x <= 9.5.5 and 9.8.0 fail to sanitize the RemoteClusterFrame payloads before audit logging them which allows a high privileged attacker with access to the audit logs to read message contents.
2024-07-03T09:15:06.617
2024-11-21T09:27:31.997
Modified
CVSSv3.1: 2.7 (LOW)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mattermost | mattermost | < 9.5.6 | Yes |
Application | mattermost | mattermost | 9.8.0 | Yes |