Description
Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to enforce proper access controls which allows user to view arbitrary post contents via the /playbook add slash command
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Update Mattermost to versions 9.7.0, 9.5.4, 9.6.2, 8.1.13 or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-35992 | Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to enforce proper access controls which allows user to view arbitrary post contents via the /playbook add slash command |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
Tue, 30 Sep 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost mattermost Server
|
|
| CPEs | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mattermost mattermost Server
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-08-02T03:30:13.174Z
Reserved: 2024-05-23T10:57:59.901Z
Link: CVE-2024-36241
Updated: 2024-06-10T17:41:23.779Z
Status : Analyzed
Published: 2024-05-26T14:15:09.830
Modified: 2025-09-30T15:28:53.153
Link: CVE-2024-36241
No data.
OpenCVE Enrichment
Updated: 2025-07-12T22:31:39Z
Weaknesses
EUVD