CVE-2024-32939
Status: AnalyzedLow (3.7)—
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2, when shared channels are enabled, fail to redact remote users' original email addresses stored in user props when email addresses are otherwise configured not to be visible in the local server."
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
- Base score: 3.7
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.22%
- Percentile among all scored CVEs: 12
- Score date: 10/7/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-284
- CWE-312
References
Raw JSON (NVD)
Show
{
"id": "CVE-2024-32939",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-32939",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-08-22T13:26:39.917242Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "responsibledisclosure@mattermost.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 2.8
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 3.7,
"attackVector": "NETWORK",
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 2.2
}
]
},
"affected": [
{
"source": "responsibledisclosure@mattermost.com",
"affectedData": [
{
"vendor": "Mattermost",
"product": "Mattermost",
"versions": [
{
"status": "affected",
"version": "9.9.0",
"versionType": "semver",
"lessThanOrEqual": "9.9.1"
},
{
"status": "affected",
"version": "9.5.0",
"versionType": "semver",
"lessThanOrEqual": "9.5.7"
},
{
"status": "affected",
"version": "9.10.0"
},
{
"status": "affected",
"version": "9.8.0",
"versionType": "semver",
"lessThanOrEqual": "9.8.2"
},
{
"status": "unaffected",
"version": "9.11.0"
},
{
"status": "unaffected",
"version": "9.9.2"
},
{
"status": "unaffected",
"version": "9.5.8"
},
{
"status": "unaffected",
"version": "9.10.1"
},
{
"status": "unaffected",
"version": "9.8.3"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2024-08-22T07:15:03.353",
"references": [
{
"url": "https://mattermost.com/security-updates",
"tags": [
"Vendor Advisory"
],
"source": "responsibledisclosure@mattermost.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "responsibledisclosure@mattermost.com",
"description": [
{
"lang": "en",
"value": "CWE-284"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-312"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2, when shared channels are enabled, fail to redact remote users' original email addresses stored in user props when email addresses are otherwise configured not to be visible in the local server.\""
},
{
"lang": "es",
"value": "Las versiones de Mattermost 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2, cuando los canales compartidos están habilitados, no se pueden redactar las direcciones de correo electrónico originales de los usuarios remotos almacenadas en las propiedades del usuario cuando las direcciones de correo electrónico están configuradas para no ser visibles en el servidor local."
}
],
"lastModified": "2026-06-17T07:30:44.293",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7FEEA8D7-745A-49FF-8B01-CA0D1D820D48",
"versionEndExcluding": "9.5.8",
"versionStartIncluding": "9.5.0"
},
{
"criteria": "cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9B9B4EAB-A618-4823-BECD-0BFD3D76A9D2",
"versionEndExcluding": "9.8.3",
"versionStartIncluding": "9.8.0"
},
{
"criteria": "cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A445A478-E185-49DF-8CDC-F42BBF8577D4",
"versionEndExcluding": "9.9.2",
"versionStartIncluding": "9.9.0"
},
{
"criteria": "cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0CA40F21-914D-4891-A578-02E6F35FE249",
"versionEndExcluding": "9.10.1",
"versionStartIncluding": "9.10.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "responsibledisclosure@mattermost.com"
}