Description
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to properly validate that the channel that comes from the sync message is a shared channel, when shared channels are enabled, which allows a malicious remote to add users to arbitrary teams and channels
No analysis available yet.
Remediation
Vendor Solution
Update Mattermost to versions 9.10.0, 9.9.1, 9.5.7, 9.7.6, 9.8.2 or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2562 | Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to properly validate that the channel that comes from the sync message is a shared channel, when shared channels are enabled, which allows a malicious remote to add users to arbitrary teams and channels |
Github GHSA |
GHSA-cmc8-222c-vqp9 | Mattermost failed to properly validate that the channel that comes from the sync message is a shared channel |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
Fri, 23 Aug 2024 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | NVD-CWE-noinfo |
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-08-02T15:10:58.701Z
Reserved: 2024-07-23T18:35:14.790Z
Link: CVE-2024-39274
Updated: 2024-08-02T15:10:10.358Z
Status : Analyzed
Published: 2024-08-01T15:15:12.150
Modified: 2024-08-23T14:39:29.247
Link: CVE-2024-39274
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA