CVE-2024-45843

Mattermost versions 9.5.x <= 9.5.8 fail to include themetadata endpoints ofOracle Cloud and Alibaba in the SSRF denylist, which allowsan attacker to possibly cause an SSRF if Mattermost was deployed in Oracle Cloud or Alibaba.
SSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
3.1 LOW
NETWORK
HIGH
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
MattermostCNA
3.1 LOW
NETWORK
HIGH
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
CISA-ADPADP
---
---