CVE-2024-39353: Mattermost

Low severity, CVSS 2.7. EPSS: 0.3% chance of exploitation in the next 30 days.

Mattermost versions 9.5.x <= 9.5.5 and 9.8.0 fail to sanitize the RemoteClusterFrame payloads before audit logging them which allows a high privileged attacker with access to the audit logs to read message contents.

Affected products

  • Mattermost Mattermost: from 9.5.0, before 9.5.6 (fixed in 9.5.6); version 9.8.0 only

Published 2024-07-03. Last modified 2026-06-17.