CVE-2024-32046: Mattermost Server

Medium severity, CVSS 4.3. EPSS: 0.5% chance of exploitation in the next 30 days.

Mattermost versions 9.6.x <= 9.6.0, 9.5.x <= 9.5.2, 9.4.x <= 9.4.4 and 8.1.x <= 8.1.11 fail to remove detailed error messages in API requests even if the developer mode is off which allows an attacker to get information about the server such as the full path were files are stored

Affected products

  • Mattermost Mattermost Server: from 8.1.0, before 8.1.12 (fixed in 8.1.12); from 9.4.0, before 9.4.5 (fixed in 9.4.5); from 9.5.0, before 9.5.3 (fixed in 9.5.3); from 9.6.0, before 9.6.1 (fixed in 9.6.1)

Published 2024-04-26. Last modified 2026-06-17.