Vulnerability Details CVE-2024-5272
Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to restrict the audience of the "custom_playbooks_playbook_run_updated" webhook event, which allows a guest on a channel with a playbook run linked to see all the details of the playbook run when the run is marked by finished.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 50.9%
CVSS Severity
CVSS v3 Score 4.3
Products affected by CVE-2024-5272
-
cpe:2.3:a:mattermost:mattermost_server:8.1.0
-
cpe:2.3:a:mattermost:mattermost_server:8.1.1
-
cpe:2.3:a:mattermost:mattermost_server:8.1.10
-
cpe:2.3:a:mattermost:mattermost_server:8.1.11
-
cpe:2.3:a:mattermost:mattermost_server:8.1.12
-
cpe:2.3:a:mattermost:mattermost_server:8.1.2
-
cpe:2.3:a:mattermost:mattermost_server:8.1.3
-
cpe:2.3:a:mattermost:mattermost_server:8.1.4
-
cpe:2.3:a:mattermost:mattermost_server:8.1.5
-
cpe:2.3:a:mattermost:mattermost_server:8.1.6
-
cpe:2.3:a:mattermost:mattermost_server:8.1.7
-
cpe:2.3:a:mattermost:mattermost_server:8.1.8
-
cpe:2.3:a:mattermost:mattermost_server:8.1.9
-
cpe:2.3:a:mattermost:mattermost_server:9.5.0
-
cpe:2.3:a:mattermost:mattermost_server:9.5.1
-
cpe:2.3:a:mattermost:mattermost_server:9.5.2
-
cpe:2.3:a:mattermost:mattermost_server:9.5.3
-
cpe:2.3:a:mattermost:mattermost_server:9.6.0
-
cpe:2.3:a:mattermost:mattermost_server:9.6.1