Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to disallow unsolicited invites to expose access to local channels, when shared channels are enabled, which allows a malicious remote to send an invite with the ID of an existing local channel, and that local channel will then become shared without the consent of the local admin.
References
History

Fri, 23 Aug 2024 15:00:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*:*
cpe:2.3:a:mattermost:mattermost:9.9.0:*:*:*:*:*:*:*

cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published: 2024-08-01T14:05:03.701Z

Updated: 2024-08-01T16:07:03.592Z

Reserved: 2024-07-23T17:55:45.316Z

Link: CVE-2024-39777

cve-icon Vulnrichment

Updated: 2024-08-01T14:35:29.943Z

cve-icon NVD

Status : Analyzed

Published: 2024-08-01T15:15:12.370

Modified: 2024-08-23T14:36:48.817

Link: CVE-2024-39777

cve-icon Redhat

No data.