CVE-2024-50052

MEDIUM

Mattermost <9.10.2-9.11.1-9.5.9 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 fail to check that the origin of the message in an integration action matches with the original post metadata which allows an authenticated user to delete an arbitrary post.

References (1)

Core 1
Core References

Scores

CVSS v3 4.3
EPSS 0.0026
EPSS Percentile 48.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (2)
mattermost/mattermost 0 - 8.0.0-20240926115259-20ed58906adcGo
mattermost/mattermost_server 9.5.0 - 9.5.10
Published Oct 29, 2024
Tracked Since Feb 18, 2026