Cyber Resilience

CVE-2024-32939

Medium

Published: 22 August 2024

Published
22 August 2024
Modified
23 August 2024
KEV Added
Patch
CVSS Score v3.1 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS Score 0.0028 51.7th percentile
Risk Priority 9 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2024-32939 is a medium-severity Improper Access Control (CWE-284) vulnerability in Mattermost Mattermost. Its CVSS base score is 4.3 (Medium).

Operationally, ranked in the top 48.3% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability details

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2, when shared channels are enabled, fail to redact remote users' original email addresses stored in user props when email addresses are otherwise configured not to be…

more

visible in the local server."

CWE(s)

Related Threats

No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.

Affected Assets

mattermost
mattermost
9.5.0 — 9.5.8 · 9.8.0 — 9.8.3 · 9.9.0 — 9.9.2

Mitigating Controls

Likely Mitigating Controls AI

Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.

addresses: CWE-284 CWE-312

Security training teaches access control policies and enforcement, reducing improper access control implementations.

addresses: CWE-284 CWE-312

Mapping data actions reveals potential improper access controls by showing who can perform actions on data.

addresses: CWE-284 CWE-312

Restrictive configuration settings implement and enforce proper access controls on system components.

addresses: CWE-284 CWE-312

Policy and procedures establish documented access controls and responsibilities for media, reducing improper access.

addresses: CWE-284

The access control policy and procedures directly mandate and enforce proper access control mechanisms across the organization.

addresses: CWE-284

Device lock enforces restricted access until re-authentication, directly reducing unauthorized use of active sessions.

addresses: CWE-284

Supervision and review of access control activities directly detects and remediates improper access configurations or usages.

addresses: CWE-284

Explicitly identifying and documenting actions permitted without identification or authentication enforces proper access control boundaries by defining justified exceptions.

References