CVE-2024-2447

Published Apr 5, 2024

Last updated 2 months ago

Overview

Description
Mattermost versions 8.1.x before 8.1.11, 9.3.x before 9.3.3, 9.4.x before 9.4.4, and 9.5.x before 9.5.2 fail to authenticate the source of certain types of post actions, allowing an authenticated attacker to create posts as other users via a crafted post action.
Source
responsibledisclosure@mattermost.com
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
6.5
Impact score
3.6
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Severity
MEDIUM

Weaknesses

responsibledisclosure@mattermost.com
CWE-284
nvd@nist.gov
CWE-346

Social media

Hype score
Not currently trending

Configurations