VYPR
Low severity3.1NVD Advisory· Published Sep 26, 2024· Updated Jun 17, 2026

CVE-2024-45843

CVE-2024-45843

Description

Mattermost versions 9.5.x <= 9.5.8 fail to include the metadata endpoints of Oracle Cloud and Alibaba in the SSRF denylist, which allows an attacker to possibly cause an SSRF if Mattermost was deployed in Oracle Cloud or Alibaba.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*range: >=9.5.0,<9.5.9
    • (no CPE)range: <=9.5.8
    • (no CPE)range: 9.5.0
  • osv-coords
    Range: >= 9.5.0, < 9.5.9

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.