CVE-2024-24776

CVSS V2 None CVSS V3 None
Description
Mattermost fails to check the required permissions in the POST /api/v4/channels/stats/member_count API resulting in channel member counts being leaked to a user without permissions.
Overview
  • CVE ID
  • CVE-2024-24776
  • Assigner
  • Mattermost
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-02-09T14:50:45.443Z
  • Last Modified Date
  • 2024-02-09T14:50:45.443Z
References
Reference URL Reference Tags
https://mattermost.com/security-updates
History
Created Old Value New Value Data Type Notes
2024-06-26 04:25:15 Added to TrackCVE