VYPR
Moderate severityNVD Advisory· Published Oct 29, 2024· Updated Oct 29, 2024

Private channel names leaked with Ctrl+K when ElasticSearch is enabled

CVE-2024-10241

Description

Mattermost versions 9.5.x <= 9.5.9 fail to properly filter the channel data when ElasticSearch is enabled which allows a user to get private channel names by using cmd+K/ctrl+K.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/mattermost/mattermost/server/v8Go
< 8.0.0-20240813135334-8f3a13122f558.0.0-20240813135334-8f3a13122f55

Affected products

42

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.