CVE-2024-39353: Mattermost
Low severity, CVSS 2.7. EPSS: 0.3% chance of exploitation in the next 30 days.
Mattermost versions 9.5.x <= 9.5.5 and 9.8.0 fail to sanitize the RemoteClusterFrame payloads before audit logging them which allows a high privileged attacker with access to the audit logs to read message contents.
Affected products
- Mattermost Mattermost: from 9.5.0, before 9.5.6 (fixed in 9.5.6); version 9.8.0 only
Published 2024-07-03. Last modified 2026-06-17.