Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-43813


Mattermost versions 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 fail to enforce proper access controls which allows any authenticated user, including guests, to mark any channel inside any team as read for any user.


Published

2024-08-22T07:15:04.620

Last Modified

2024-08-23T15:35:12.617

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 4.3 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-284
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application mattermost mattermost < 9.5.8 Yes
Application mattermost mattermost < 9.10.1 Yes

References