CVE-2024-42406
Estado: AnalizadaMedia (5.4)—
Mattermost versions 9.11.x <= 9.11.0, 9.10.x <= 9.10.1, 9.9.x <= 9.9.2 and 9.5.x <= 9.5.8 fail to properly authorize requests when viewing archived channels is disabled, which allows an attacker to retrieve post and file information about archived channels. Examples are flagged or unread posts as well as files.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
- Puntuación base: 5.4
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.22%
- Percentil entre todas las CVEs puntuadas: 12
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-284
- NVD-CWE-noinfo
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-42406",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-42406",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-09-26T13:11:20.126365Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "responsibledisclosure@mattermost.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.4,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 2.5,
"exploitabilityScore": 2.8
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.4,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 2.5,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "responsibledisclosure@mattermost.com",
"affectedData": [
{
"vendor": "Mattermost",
"product": "Mattermost",
"versions": [
{
"status": "affected",
"version": "9.11.0"
},
{
"status": "affected",
"version": "9.10.0",
"versionType": "semver",
"lessThanOrEqual": "9.10.1"
},
{
"status": "affected",
"version": "9.9.0",
"versionType": "semver",
"lessThanOrEqual": "9.9.2"
},
{
"status": "affected",
"version": "9.5.0",
"versionType": "semver",
"lessThanOrEqual": "9.5.8"
},
{
"status": "unaffected",
"version": "10.0.0"
},
{
"status": "unaffected",
"version": "9.11.1"
},
{
"status": "unaffected",
"version": "9.10.2"
},
{
"status": "unaffected",
"version": "9.9.3"
},
{
"status": "unaffected",
"version": "9.5.9"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2024-09-26T08:15:05.810",
"references": [
{
"url": "https://mattermost.com/security-updates",
"tags": [
"Vendor Advisory"
],
"source": "responsibledisclosure@mattermost.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "responsibledisclosure@mattermost.com",
"description": [
{
"lang": "en",
"value": "CWE-284"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Mattermost versions 9.11.x <= 9.11.0, 9.10.x <= 9.10.1, 9.9.x <= 9.9.2 and 9.5.x <= 9.5.8 fail to properly authorize requests when viewing archived channels is disabled, which allows an attacker to retrieve post and file information about archived channels. Examples are flagged or unread posts as well as files."
},
{
"lang": "es",
"value": "Las versiones 9.11.x <= 9.11.0, 9.10.x <= 9.10.1, 9.9.x <= 9.9.2 y 9.5.x <= 9.5.8 de Mattermost no autorizan correctamente las solicitudes cuando la visualización de canales archivados está deshabilitada, lo que permite a un atacante recuperar información de publicaciones y archivos sobre canales archivados. Algunos ejemplos son las publicaciones marcadas o no leídas, así como los archivos."
}
],
"lastModified": "2026-06-17T07:49:24.200",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BC97EDD1-AD9D-484B-99B0-D49541EFBA52",
"versionEndExcluding": "9.5.9",
"versionStartIncluding": "9.5.0"
},
{
"criteria": "cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "20276949-478F-4F2C-9D07-F9B3C04CADD9",
"versionEndExcluding": "9.9.3",
"versionStartIncluding": "9.9.0"
},
{
"criteria": "cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6AE34CB3-C7F7-4AAD-888E-5057ACBE9BC4",
"versionEndExcluding": "9.10.2",
"versionStartIncluding": "9.10.0"
},
{
"criteria": "cpe:2.3:a:mattermost:mattermost_server:9.11.0:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E7436086-F0AC-4AB8-B611-7B8E1AE2E4F9"
},
{
"criteria": "cpe:2.3:a:mattermost:mattermost_server:9.11.0:rc1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D5310C1D-DA5F-46B5-BA33-F7C3D6A63C2F"
},
{
"criteria": "cpe:2.3:a:mattermost:mattermost_server:9.11.0:rc2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BCE22F86-00E2-42E0-8343-D3AD818AA943"
},
{
"criteria": "cpe:2.3:a:mattermost:mattermost_server:9.11.0:rc3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "641065E7-F36F-42F3-A098-B7131DB0D2F5"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "responsibledisclosure@mattermost.com"
}