<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 02:17:05 +0000</lastBuildDate>
    <item>
      <title>CVE-2024-42406 — Unauthorized access on archived channels</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2024-42406</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Mattermost&lt;/p&gt;
&lt;p&gt;Mattermost versions 9.11.x &amp;lt;= 9.11.0, 9.10.x &amp;lt;= 9.10.1, 9.9.x &amp;lt;= 9.9.2 and 9.5.x &amp;lt;= 9.5.8 fail to properly authorize requests when viewing archived channels is disabled, which allows an attacker to retrieve post and file information about archived channels. Examples are flagged or unread posts as well as files.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Mattermost&lt;/p&gt;
&lt;p&gt;Mattermost versions 9.11.x &amp;lt;= 9.11.0, 9.10.x &amp;lt;= 9.10.1, 9.9.x &amp;lt;= 9.9.2 and 9.5.x &amp;lt;= 9.5.8 fail to properly authorize requests when viewing archived channels is disabled, which allows an attacker to retrieve post and file information about archived channels. Examples are flagged or unread posts as well as files.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2024-42406</guid>
    </item>
  </channel>
</rss>
