2024-08-01 16:03:14 +00:00
{
"id" : "CVE-2024-41162" ,
"sourceIdentifier" : "responsibledisclosure@mattermost.com" ,
"published" : "2024-08-01T15:15:13.627" ,
2024-09-04 18:03:19 +00:00
"lastModified" : "2024-09-04T17:03:53.010" ,
"vulnStatus" : "Analyzed" ,
2024-08-01 16:03:14 +00:00
"cveTags" : [ ] ,
"descriptions" : [
{
"lang" : "en" ,
"value" : "Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to disallow\u00a0the modification of local channels by a remote, when shared channels are enabled, which allows\u00a0a malicious remote to make an arbitrary local channel read-only."
2024-08-04 02:03:13 +00:00
} ,
{
"lang" : "es" ,
"value" : " Las versiones de Mattermost 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 y 9.8.x <= 9.8.1 no permiten la modificaci\u00f3n de canales locales mediante un control remoto, cuando Los canales compartidos est\u00e1n habilitados, lo que permite que un control remoto malicioso convierta un canal local arbitrario en solo lectura."
2024-08-01 16:03:14 +00:00
}
] ,
"metrics" : {
"cvssMetricV31" : [
2024-09-04 18:03:19 +00:00
{
2024-12-08 03:06:42 +00:00
"source" : "responsibledisclosure@mattermost.com" ,
"type" : "Secondary" ,
2024-09-04 18:03:19 +00:00
"cvssData" : {
"version" : "3.1" ,
2024-12-08 03:06:42 +00:00
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:N" ,
"baseScore" : 4.1 ,
"baseSeverity" : "MEDIUM" ,
2024-09-04 18:03:19 +00:00
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
2024-12-08 03:06:42 +00:00
"privilegesRequired" : "HIGH" ,
2024-09-04 18:03:19 +00:00
"userInteraction" : "NONE" ,
2024-12-08 03:06:42 +00:00
"scope" : "CHANGED" ,
2024-09-04 18:03:19 +00:00
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "LOW" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "NONE"
2024-09-04 18:03:19 +00:00
} ,
2024-12-08 03:06:42 +00:00
"exploitabilityScore" : 2.3 ,
2024-09-04 18:03:19 +00:00
"impactScore" : 1.4
} ,
2024-08-01 16:03:14 +00:00
{
2024-12-08 03:06:42 +00:00
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
2024-08-01 16:03:14 +00:00
"cvssData" : {
"version" : "3.1" ,
2024-12-08 03:06:42 +00:00
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" ,
"baseScore" : 4.3 ,
"baseSeverity" : "MEDIUM" ,
2024-08-01 16:03:14 +00:00
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
2024-12-08 03:06:42 +00:00
"privilegesRequired" : "LOW" ,
2024-08-01 16:03:14 +00:00
"userInteraction" : "NONE" ,
2024-12-08 03:06:42 +00:00
"scope" : "UNCHANGED" ,
2024-08-01 16:03:14 +00:00
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "LOW" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "NONE"
2024-08-01 16:03:14 +00:00
} ,
2024-12-08 03:06:42 +00:00
"exploitabilityScore" : 2.8 ,
2024-08-01 16:03:14 +00:00
"impactScore" : 1.4
}
]
} ,
"weaknesses" : [
2024-09-04 18:03:19 +00:00
{
2024-12-08 03:06:42 +00:00
"source" : "responsibledisclosure@mattermost.com" ,
"type" : "Secondary" ,
2024-09-04 18:03:19 +00:00
"description" : [
{
"lang" : "en" ,
2024-12-08 03:06:42 +00:00
"value" : "CWE-284"
2024-09-04 18:03:19 +00:00
}
]
} ,
2024-08-01 16:03:14 +00:00
{
2024-12-08 03:06:42 +00:00
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
2024-08-01 16:03:14 +00:00
"description" : [
{
"lang" : "en" ,
2024-12-08 03:06:42 +00:00
"value" : "NVD-CWE-noinfo"
2024-08-01 16:03:14 +00:00
}
]
}
] ,
2024-09-04 18:03:19 +00:00
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "9.5.0" ,
"versionEndExcluding" : "9.5.7" ,
"matchCriteriaId" : "CBEB8F40-C2DE-4E6F-8772-1BBCA44795A8"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "9.7.0" ,
"versionEndExcluding" : "9.7.6" ,
"matchCriteriaId" : "B5C9F963-57DF-41E2-AA46-242317D93786"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "9.8.0" ,
"versionEndExcluding" : "9.8.2" ,
"matchCriteriaId" : "6B4559B7-83E7-41B2-96A8-51F467CCD882"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mattermost:mattermost_server:9.9.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "4BE71910-C7C4-4F33-BFD4-40D2EAA56DB1"
}
]
}
]
}
] ,
2024-08-01 16:03:14 +00:00
"references" : [
{
"url" : "https://mattermost.com/security-updates" ,
2024-09-04 18:03:19 +00:00
"source" : "responsibledisclosure@mattermost.com" ,
"tags" : [
"Vendor Advisory"
]
2024-08-01 16:03:14 +00:00
}
]
}