CVE-2024-1942: Mattermost Server
Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.
Mattermost versions 8.1.x before 8.1.9, 9.2.x before 9.2.5, and 9.3.0 fail to sanitize the metadata on posts containing permalinks under specific conditions, which allows an authenticated attacker to access the contents of individual posts in channels they are not a member of.
Affected products
- Mattermost Mattermost Server: from 8.1.0, before 8.1.9 (fixed in 8.1.9); from 9.2.0, before 9.2.5 (fixed in 9.2.5); version 9.3.0 only
Published 2024-02-29. Last modified 2026-06-17.