CVE-2024-45843
26.09.2024, 08:15
Mattermost versions 9.5.x <= 9.5.8 fail to include themetadata endpoints ofOracle Cloud and Alibaba in the SSRF denylist, which allowsan attacker to possibly cause an SSRF if Mattermost was deployed in Oracle Cloud or Alibaba.
Vendor | Product | Version |
---|---|---|
mattermost | mattermost_server | 9.5.0 ≤ 𝑥 < 9.5.9 |
𝑥
= Vulnerable software versions
References