Lack of permissions prompting when opening external URLs
Vulnerability Description
Mattermost Desktop App versions <=5.7.0 fail to correctly prompt for permission when opening external URLs which allows a remote attacker to force a victim over the Internet to run arbitrary programs on the victim's system via custom URI schemes.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-37182
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- gee-netics (gee-netics)
References
More from Mattermost
View All →Affected Vendor
Mattermost
View all reports →