Vulnerability Details CVE-2024-39807
Mattermost versions 9.5.x <= 9.5.5 and 9.8.0 fail to properly sanitize the recipients of a webhook event which allows an attacker monitoring webhook events to retrieve the channel IDs of archived or restored channels.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 53.5%
CVSS Severity
CVSS v3 Score 3.1
Products affected by CVE-2024-39807
-
cpe:2.3:a:mattermost:mattermost:9.5.0
-
cpe:2.3:a:mattermost:mattermost:9.5.1
-
cpe:2.3:a:mattermost:mattermost:9.5.2
-
cpe:2.3:a:mattermost:mattermost:9.5.3
-
cpe:2.3:a:mattermost:mattermost:9.5.4
-
cpe:2.3:a:mattermost:mattermost:9.5.5
-
cpe:2.3:a:mattermost:mattermost:9.8.0