Description
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to disallow the modification of local users when syncing users in shared channels. which allows a malicious remote to overwrite an existing local user.
No analysis available yet.
Remediation
Vendor Solution
Update Mattermost to versions 9.10.0, 9.9.1, 9.5.7, 9.7.6, 9.8.2 or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2500 | Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to disallow the modification of local users when syncing users in shared channels. which allows a malicious remote to overwrite an existing local user. |
Github GHSA |
GHSA-56mc-f9w7-2wxq | Mattermost failed to disallow the modification of local users when syncing users in shared channels |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
Fri, 23 Aug 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost
Mattermost mattermost |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*:* cpe:2.3:a:mattermost:mattermost:9.9.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Mattermost
Mattermost mattermost |
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-08-05T16:57:11.289Z
Reserved: 2024-07-23T17:55:45.350Z
Link: CVE-2024-36492
Updated: 2024-08-05T16:57:06.440Z
Status : Analyzed
Published: 2024-08-01T15:15:11.810
Modified: 2024-08-23T14:51:08.580
Link: CVE-2024-36492
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA