ZeroHour

CVE-2024-45843

CVSS 3.1
5.4 medium
EPSS
<1%p12
Published
()
Modified
Description

Mattermost versions 9.5.x <= 9.5.8 fail to include the metadata endpoints of Oracle Cloud and Alibaba in the SSRF denylist, which allows an attacker to possibly cause an SSRF if Mattermost was deployed in Oracle Cloud or Alibaba.

Vendors
mattermost
Products
mattermost server
Weakness
CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.