CVE-2024-23488

LOW

Mattermost < 8.1.9 and 9.0.0-9.4.2 - Improper Access Control in Archived Channel File Attachments

Title source: llm
STIX 2.1

Description

Mattermost fails to properly restrict the access of files attached to posts in an archived channel, resulting in members being able to access files of archived channels even if the “Allow users to view archived channels” option is disabled.

References (1)

Core 1
Core References

Scores

CVSS v3 3.1
EPSS 0.0020
EPSS Percentile 41.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-284
Status published
Products (2)
mattermost/mattermost 9.0.0 - 9.4.2Go
mattermost/mattermost_server < 8.1.9
Published Feb 29, 2024
Tracked Since Feb 18, 2026