Description
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6 fail to properly validate synced reactions, when shared channels are enabled, which allows a malicious remote to create arbitrary reactions on arbitrary posts
No analysis available yet.
Remediation
Vendor Solution
Update Mattermost to versions 9.10.0, 9.9.1, 9.5.7 or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2607 | Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6 fail to properly validate synced reactions, when shared channels are enabled, which allows a malicious remote to create arbitrary reactions on arbitrary posts |
Github GHSA |
GHSA-jq3g-xqpx-37x3 | Mattermost failed to properly validate synced reactions |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
Fri, 23 Aug 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost
Mattermost mattermost |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*:* cpe:2.3:a:mattermost:mattermost:9.9.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Mattermost
Mattermost mattermost |
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-08-01T14:35:07.529Z
Reserved: 2024-07-23T19:00:08.575Z
Link: CVE-2024-29977
Updated: 2024-08-01T14:35:03.278Z
Status : Analyzed
Published: 2024-08-01T15:15:11.290
Modified: 2024-08-23T14:52:19.923
Link: CVE-2024-29977
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA