Mattermost versions 9.5.x <= 9.5.9 fail to properly filter the channel data when ElasticSearch is enabled which allows a user to get private channel names by using cmd+K/ctrl+K.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-2970 Mattermost versions 9.5.x <= 9.5.9 fail to properly filter the channel data when ElasticSearch is enabled which allows a user to get private channel names by using cmd+K/ctrl+K.
Github GHSA Github GHSA GHSA-6mvp-gh77-7vwh Mattermost Server allows user to get private channel names
Fixes

Solution

Update Mattermost Server to versions 9.8.0, 9.5.10 or higher.


Workaround

No workaround given by the vendor.

References
History

Wed, 01 Oct 2025 02:15:00 +0900

Type Values Removed Values Added
First Time appeared Mattermost mattermost Server
CPEs cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
Vendors & Products Mattermost mattermost Server

Tue, 15 Jul 2025 22:45:00 +0900

Type Values Removed Values Added
Metrics epss

{'score': 0.00064}

epss

{'score': 0.00075}


Tue, 29 Oct 2024 22:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 29 Oct 2024 17:15:00 +0900

Type Values Removed Values Added
Description Mattermost versions 9.5.x <= 9.5.9 fail to properly filter the channel data when ElasticSearch is enabled which allows a user to get private channel names by using cmd+K/ctrl+K.
Title Private channel names leaked with Ctrl+K when ElasticSearch is enabled
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2024-10-29T12:52:53.569Z

Reserved: 2024-10-22T09:22:11.172Z

Link: CVE-2024-10241

cve-icon Vulnrichment

Updated: 2024-10-29T12:52:50.268Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-29T08:15:11.990

Modified: 2025-09-30T17:09:36.340

Link: CVE-2024-10241

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-07-13T01:01:22Z

Weaknesses