Description
Mattermost versions 9.5.x <= 9.5.5 and 9.8.0, when using shared channels with multiple remote servers connected, fail to check that the remote server A requesting the server B to update the profile picture of a user is the remote that actually has the user as a local one . This allows a malicious remote A to change the profile images of users that belong to another remote server C that is connected to the server A.
No analysis available yet.
Remediation
Vendor Solution
Update Mattermost to versions 9.9.0, 9.8.1, 9.5.6 or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-36003 | Mattermost versions 9.5.x <= 9.5.5 and 9.8.0, when using shared channels with multiple remote servers connected, fail to check that the remote server A requesting the server B to update the profile picture of a user is the remote that actually has the user as a local one . This allows a malicious remote A to change the profile images of users that belong to another remote server C that is connected to the server A. |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
No history.
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-08-02T03:37:03.658Z
Reserved: 2024-07-01T10:22:11.588Z
Link: CVE-2024-36257
Updated: 2024-08-02T03:37:03.658Z
Status : Modified
Published: 2024-07-03T09:15:06.247
Modified: 2024-11-21T09:21:56.843
Link: CVE-2024-36257
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD