Vulnerability Description
Mattermost versions 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 fail to enforce proper access controls which allows any authenticated user, including guests, to mark any channel inside any team as read for any user.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mattermost | Mattermost | >= 9.5.0, < 9.5.8 |
Related Weaknesses (CWE)
References
- https://mattermost.com/security-updatesVendor Advisory
FAQ
What is CVE-2024-43813?
CVE-2024-43813 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Mattermost versions 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 fail to enforce proper access controls which allows any authenticated user, including guests, to mark any channel inside any team as read for any u...
How severe is CVE-2024-43813?
CVE-2024-43813 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-43813?
Check the references section above for vendor advisories and patch information. Affected products include: Mattermost Mattermost.