CVE-2024-45843: Mattermost Server
Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.
Mattermost versions 9.5.x <= 9.5.8 fail to include the metadata endpoints of Oracle Cloud and Alibaba in the SSRF denylist, which allows an attacker to possibly cause an SSRF if Mattermost was deployed in Oracle Cloud or Alibaba.
Affected products
- Mattermost Mattermost Server: from 9.5.0, before 9.5.9 (fixed in 9.5.9)
Published 2024-09-26. Last modified 2026-06-17.