CVE-2024-1887: Mattermost Server
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
Mattermost fails to check if compliance export is enabled when fetching posts of public channels allowing a user that is not a member of the public channel to fetch the posts, which will not be audited in the compliance export.
Affected products
- Mattermost Mattermost Server: before 8.1.9 (fixed in 8.1.9); from 9.2.0, before 9.2.5 (fixed in 9.2.5); from 9.3.0, before 9.3.1 (fixed in 9.3.1)
Published 2024-02-29. Last modified 2026-06-17.