Beveiligingsadvies

CVE-2024-45843

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2024-09-26 08:03:41
Laatst bijgewerkt 2024-09-26 13:11:54
Toegewezen door Mattermost
CVSS-score 3.1
Status PUBLISHED

Beschrijving

Mattermost versions 9.5.x <= 9.5.8 fail to include the metadata endpoints of Oracle Cloud and Alibaba in the SSRF denylist, which allows an attacker to possibly cause an SSRF if Mattermost was deployed in Oracle Cloud or Alibaba.