2024-09-26 10:03:17 +00:00
{
"id" : "CVE-2024-45843" ,
"sourceIdentifier" : "responsibledisclosure@mattermost.com" ,
"published" : "2024-09-26T08:15:06.020" ,
2024-09-26 20:03:19 +00:00
"lastModified" : "2024-09-26T18:42:26.697" ,
"vulnStatus" : "Analyzed" ,
2024-09-26 10:03:17 +00:00
"cveTags" : [ ] ,
"descriptions" : [
{
"lang" : "en" ,
"value" : "Mattermost versions 9.5.x <= 9.5.8 fail to include the\u00a0metadata endpoints of\u00a0Oracle Cloud and Alibaba in the SSRF denylist, which allows\u00a0an attacker to possibly cause an SSRF if Mattermost was deployed in Oracle Cloud or Alibaba."
2024-09-26 14:03:23 +00:00
} ,
{
"lang" : "es" ,
"value" : "Las versiones 9.5.x <= 9.5.8 de Mattermost no incluyen los endpoints de metadatos de Oracle Cloud y Alibaba en la lista de denegaci\u00f3n de SSRF, lo que permite que un atacante posiblemente provoque una SSRF si Mattermost se implement\u00f3 en Oracle Cloud o Alibaba."
2024-09-26 10:03:17 +00:00
}
] ,
"metrics" : {
"cvssMetricV31" : [
2024-09-26 20:03:19 +00:00
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "LOW" ,
"integrityImpact" : "LOW" ,
"availabilityImpact" : "NONE" ,
"baseScore" : 5.4 ,
"baseSeverity" : "MEDIUM"
} ,
"exploitabilityScore" : 2.8 ,
"impactScore" : 2.5
} ,
2024-09-26 10:03:17 +00:00
{
"source" : "responsibledisclosure@mattermost.com" ,
"type" : "Secondary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "HIGH" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "LOW" ,
"integrityImpact" : "NONE" ,
"availabilityImpact" : "NONE" ,
"baseScore" : 3.1 ,
"baseSeverity" : "LOW"
} ,
"exploitabilityScore" : 1.6 ,
"impactScore" : 1.4
}
]
} ,
"weaknesses" : [
2024-09-26 20:03:19 +00:00
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-918"
}
]
} ,
2024-09-26 10:03:17 +00:00
{
"source" : "responsibledisclosure@mattermost.com" ,
"type" : "Secondary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-918"
}
]
}
] ,
2024-09-26 20:03:19 +00:00
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "9.5.0" ,
"versionEndExcluding" : "9.5.9" ,
"matchCriteriaId" : "BC97EDD1-AD9D-484B-99B0-D49541EFBA52"
}
]
}
]
}
] ,
2024-09-26 10:03:17 +00:00
"references" : [
{
"url" : "https://mattermost.com/security-updates" ,
2024-09-26 20:03:19 +00:00
"source" : "responsibledisclosure@mattermost.com" ,
"tags" : [
"Vendor Advisory"
]
2024-09-26 10:03:17 +00:00
}
]
}