CVE-2024-9155 is a medium-severity vulnerability affecting Mattermost versions 9.10.1, 9.9.2, and 9.5.8 and earlier, where the platform fails to restrict access to channel files not yet linked to a post. This allows authenticated attackers to view these unlinked files within channels they are members of. The vulnerability has a CVSS score of 4.3 (MEDIUM), indicating low attack complexity and a potential for limited confidentiality impact, but no integrity or availability impact. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9.5.0, < 9.5.9CPE matchmatch criteria | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* | ||
>= 9.9.0, < 9.9.3CPE matchmatch criteria | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* | ||
>= 9.10.0, < 9.10.2CPE matchmatch criteria | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* | ||
>= 9.10.0, <= 9.10.1CPE match | cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*:* | ||
>= 9.5.0, <= 9.5.8CPE match | cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.