« Volver al listado

CVE-2024-2447

Estado: AnalizadaMedia (6.5)—

Mattermost versions 8.1.x before 8.1.11, 9.3.x before 9.3.3, 9.4.x before 9.4.4, and 9.5.x before 9.5.2 fail to authenticate the source of certain types of post actions, allowing an authenticated attacker to create posts as other users via a crafted post action.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-2447",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-2447",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-07-29T15:51:10.928653Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "responsibledisclosure@mattermost.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "responsibledisclosure@mattermost.com",
      "affectedData": [
        {
          "vendor": "Mattermost",
          "product": "Mattermost",
          "versions": [
            {
              "status": "affected",
              "version": "9.5.0",
              "versionType": "semver",
              "lessThanOrEqual": "9.5.1"
            },
            {
              "status": "affected",
              "version": "9.4.0",
              "versionType": "semver",
              "lessThanOrEqual": "9.4.3"
            },
            {
              "status": "affected",
              "version": "9.3.0",
              "versionType": "semver",
              "lessThanOrEqual": "9.3.2"
            },
            {
              "status": "affected",
              "version": "8.1.0",
              "versionType": "semver",
              "lessThanOrEqual": "8.1.10"
            },
            {
              "status": "unaffected",
              "version": "9.6.0"
            },
            {
              "status": "unaffected",
              "version": "9.5.2"
            },
            {
              "status": "unaffected",
              "version": "9.4.4"
            },
            {
              "status": "unaffected",
              "version": "9.3.3"
            },
            {
              "status": "unaffected",
              "version": "8.1.11"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2024-04-05T09:15:09.860",
  "references": [
    {
      "url": "https://mattermost.com/security-updates",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "responsibledisclosure@mattermost.com"
    },
    {
      "url": "https://mattermost.com/security-updates",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "responsibledisclosure@mattermost.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-284"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-346"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Mattermost versions 8.1.x before 8.1.11, 9.3.x before 9.3.3, 9.4.x before 9.4.4, and 9.5.x before 9.5.2 fail to authenticate the source of certain types of post actions, allowing an authenticated attacker to create posts as other users via a crafted post action.\n\n"
    },
    {
      "lang": "es",
      "value": "Las versiones de Mattermost 8.1.x anteriores a 8.1.11, 9.3.x anteriores a 9.3.3, 9.4.x anteriores a 9.4.4 y 9.5.x anteriores a 9.5.2 no logran autenticar la fuente de ciertos tipos de acciones de publicación, lo que permite una atacante autenticado para crear publicaciones como otros usuarios a través de una acción de publicación manipulada."
    }
  ],
  "lastModified": "2026-06-17T07:24:33.283",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "66FEDCF9-277A-4D60-8A28-948068A10F91",
              "versionEndExcluding": "8.1.11",
              "versionStartIncluding": "8.1.0"
            },
            {
              "criteria": "cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B4A105B6-CFF8-4FF0-A70D-F3C390AE0FAD",
              "versionEndExcluding": "9.3.3",
              "versionStartIncluding": "9.3.0"
            },
            {
              "criteria": "cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "600DCF59-6535-484C-9DDC-E33834B90B25",
              "versionEndExcluding": "9.4.4",
              "versionStartIncluding": "9.4.0"
            },
            {
              "criteria": "cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7A768D77-9FF0-4C1B-81B0-AD2187832E62",
              "versionEndExcluding": "9.5.2",
              "versionStartIncluding": "9.5.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "responsibledisclosure@mattermost.com"
}