CVE-2024-1949

LOW

Mattermost <8.1.9-9.4.2 - Privilege Escalation

Title source: llm
STIX 2.1

Description

A race condition in Mattermost versions 8.1.x before 8.1.9, and 9.4.x before 9.4.2 allows an authenticated attacker to gain unauthorized access to individual posts' contents via carefully timed post creation while another user deletes posts.

References (1)

Core 1
Core References

Scores

CVSS v3 2.6
EPSS 0.0027
EPSS Percentile 50.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-362 CWE-200
Status published
Products (2)
mattermost/mattermost 9.0.0 - 9.4.2Go
mattermost/mattermost_server 8.1.0 - 8.1.9
Published Feb 29, 2024
Tracked Since Feb 18, 2026