Mattermost versions 9.6.x <= 9.6.0, 9.5.x <= 9.5.2, 9.4.x <= 9.4.4 and 8.1.x <= 8.1.11 fail to remove detailed error messages in API requests even if the developer mode is off which allows an attacker to get information about the server such as the full path were files are stored
References
Link | Resource |
---|---|
https://mattermost.com/security-updates | Vendor Advisory |
https://mattermost.com/security-updates | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
12 May 2025, 13:39
Type | Values Removed | Values Added |
---|---|---|
References | () https://mattermost.com/security-updates - Vendor Advisory | |
First Time |
Mattermost mattermost Server
Mattermost |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.3 |
CWE | CWE-209 | |
CPE | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* |
26 Apr 2024, 09:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-04-26 09:15
Updated : 2025-05-12 13:39
NVD link : CVE-2024-32046
Mitre link : CVE-2024-32046
JSON object : View
Products Affected
mattermost
- mattermost_server
CWE
CWE-209
Generation of Error Message Containing Sensitive Information