Description

Mattermost versions 10.0.x <= 10.0.0 and 9.11.x <= 9.11.2 fail to properly query ElasticSearch when searching for the channel name in channel switcher which allows an attacker to get private channels names of channels that they are not a member of, when Elasticsearch v8 was enabled.

INFO

Published Date :

2024-11-09T17:19:35.639Z

Last Modified :

2024-11-12T14:52:07.690Z

Source :

Mattermost
AFFECTED PRODUCTS

The following products are affected by CVE-2024-52032 vulnerability.

Vendors Products
Mattermost
  • Mattermost Server
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2024-52032.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact