« Volver al listado

CVE-2024-5272

Estado: AnalizadaMedia (4.3)—

Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to restrict the audience of the "custom_playbooks_playbook_run_updated" webhook event, which allows a guest on a channel with a playbook run linked to see all the details of the playbook run when the run is marked by finished.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-5272",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-5272",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-05-28T14:54:17.605429Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "responsibledisclosure@mattermost.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "responsibledisclosure@mattermost.com",
      "affectedData": [
        {
          "vendor": "Mattermost",
          "product": "Mattermost",
          "versions": [
            {
              "status": "affected",
              "version": "9.5.0",
              "versionType": "semver",
              "lessThanOrEqual": "9.5.3"
            },
            {
              "status": "affected",
              "version": "9.6.0",
              "versionType": "semver",
              "lessThanOrEqual": "9.6.1"
            },
            {
              "status": "affected",
              "version": "8.1.0",
              "versionType": "semver",
              "lessThanOrEqual": "8.1.12"
            },
            {
              "status": "unaffected",
              "version": "9.7.0"
            },
            {
              "status": "unaffected",
              "version": "9.5.4"
            },
            {
              "status": "unaffected",
              "version": "9.6.2"
            },
            {
              "status": "unaffected",
              "version": "8.1.13"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:mattermost:mattermost:-:*:*:*:*:*:*:*"
          ],
          "vendor": "mattermost",
          "product": "mattermost",
          "versions": [
            {
              "status": "affected",
              "version": "9.5.0",
              "versionType": "custom",
              "lessThanOrEqual": "9.5.3"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:a:mattermost:mattermost:-:*:*:*:*:*:*:*"
          ],
          "vendor": "mattermost",
          "product": "mattermost",
          "versions": [
            {
              "status": "affected",
              "version": "9.6.0",
              "versionType": "custom",
              "lessThanOrEqual": "9.6.1"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:a:mattermost:mattermost:-:*:*:*:*:*:*:*"
          ],
          "vendor": "mattermost",
          "product": "mattermost",
          "versions": [
            {
              "status": "affected",
              "version": "8.1.0",
              "versionType": "custom",
              "lessThanOrEqual": "8.1.12"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:a:mattermost:mattermost:-:*:*:*:*:*:*:*"
          ],
          "vendor": "mattermost",
          "product": "mattermost",
          "versions": [
            {
              "status": "unaffected",
              "version": "9.7.0"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:a:mattermost:mattermost:-:*:*:*:*:*:*:*"
          ],
          "vendor": "mattermost",
          "product": "mattermost",
          "versions": [
            {
              "status": "unaffected",
              "version": "9.5.4"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:a:mattermost:mattermost:-:*:*:*:*:*:*:*"
          ],
          "vendor": "mattermost",
          "product": "mattermost",
          "versions": [
            {
              "status": "unaffected",
              "version": "9.6.2"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:a:mattermost:mattermost:-:*:*:*:*:*:*:*"
          ],
          "vendor": "mattermost",
          "product": "mattermost",
          "versions": [
            {
              "status": "unaffected",
              "version": "8.1.13"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-05-26T14:15:10.537",
  "references": [
    {
      "url": "https://mattermost.com/security-updates",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "responsibledisclosure@mattermost.com"
    },
    {
      "url": "https://mattermost.com/security-updates",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "responsibledisclosure@mattermost.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-284"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to restrict the audience of the \"custom_playbooks_playbook_run_updated\" webhook event, which allows a guest on a channel with a playbook run linked to see all the details of the playbook run when the run is marked by finished."
    },
    {
      "lang": "es",
      "value": "Las versiones 9.5.x &lt;= 9.5.3, 9.6.x &lt;= 9.6.1, 8.1.x &lt;= 8.1.12 de Mattermost no restringen la audiencia del evento de webhook \"custom_playbooks_playbook_run_updated\", que permite a un invitado en un canal con un Ejecución del libro de jugadas vinculada para ver todos los detalles de la ejecución del libro de jugadas cuando la ejecución está marcada como finalizada."
    }
  ],
  "lastModified": "2026-06-17T08:15:35.213",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "47448305-8E05-4AEE-9E7B-D52AC86C7370",
              "versionEndExcluding": "8.1.13",
              "versionStartIncluding": "8.1.0"
            },
            {
              "criteria": "cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "73F3450F-7A4F-450D-BC68-E726D347636F",
              "versionEndExcluding": "9.5.4",
              "versionStartIncluding": "9.5.0"
            },
            {
              "criteria": "cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B3E36367-4F29-45EE-BCF6-CDAA8E599E85",
              "versionEndExcluding": "9.6.2",
              "versionStartIncluding": "9.6.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "responsibledisclosure@mattermost.com"
}