CVE-2024-10241

Published Oct 29, 2024

Last updated 19 days ago

Overview

Description
Mattermost versions 9.5.x <= 9.5.9 fail to properly filter the channel data when ElasticSearch is enabled which allows a user to get private channel names by using cmd+K/ctrl+K.
Source
responsibledisclosure@mattermost.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
4.3
Impact score
1.4
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Severity
MEDIUM

Weaknesses

responsibledisclosure@mattermost.com
CWE-284

Social media

Hype score
Not currently trending
  1. 🚨 CVE-2024-10241 (Published: 2024-10-29) affects Mattermost. Ensure your systems are updated to the latest version to mitigate potential exploits. For detailed remediation steps and security updates, visit: https://t.co/UQcJ9OJ1kn. Stay secure! 🔒 #CyberSecurity #CVE

    @transilienceai

    1 Nov 2024

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 🚨 CVE-2024-10241 (Published: 2024-10-29) affects Mattermost. Ensure your systems are updated to the latest version to mitigate vulnerabilities. Check the security updates for detailed remediation steps: https://t.co/UQcJ9OJ1kn. Stay secure! #CyberSecurity #CVE

    @transilienceai

    1 Nov 2024

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 🔒 CVE-2024-10241 (Published: 2024-10-29) - A medium-severity vulnerability affects Mattermost. Ensure you're using the latest version to mitigate risks. For detailed remediation steps and updates, visit: https://t.co/UQcJ9OJ1kn. Stay secure! #CyberSecurity #Mattermost

    @transilienceai

    1 Nov 2024

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🔒 CVE-2024-10241 (Published: 2024-10-29) - A medium severity vulnerability affects Mattermost. Ensure your installations are updated to the latest version to mitigate risks. For detailed remediation steps, visit: https://t.co/UQcJ9OJ1kn. Stay secure! #CyberSecurity #Mattermost

    @transilienceai

    1 Nov 2024

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. CVE-2024-10241 Mattermost versions 9.5.x &lt;= 9.5.9 fail to properly filter the channel data when ElasticSearch is enabled which allows a user to get private channel names by using cm… https://t.co/541Y7Ti1sA

    @CVEnew

    29 Oct 2024

    566 Impressions

    2 Retweets

    3 Likes

    2 Bookmarks

    0 Replies

    0 Quotes