Description
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to properly safeguard an error handling which allows a malicious remote to permanently delete local data by abusing dangerous error handling, when share channels were enabled.
No analysis available yet.
Remediation
Vendor Solution
Update Mattermost to versions 9.10.0, 9.9.1, 9.5.7, 9.7.6, 9.8.2 or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2523 | Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to properly safeguard an error handling which allows a malicious remote to permanently delete local data by abusing dangerous error handling, when share channels were enabled. |
Github GHSA |
GHSA-762m-4cx6-6mf4 | Mattermost allows a remote actor to permanently delete local data by abusing dangerous error handling |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
Fri, 23 Aug 2024 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost
Mattermost mattermost |
|
| CPEs | cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*:* cpe:2.3:a:mattermost:mattermost:9.9.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Mattermost
Mattermost mattermost |
Wed, 07 Aug 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-08-07T14:09:31.969Z
Reserved: 2024-07-23T17:55:45.288Z
Link: CVE-2024-39832
Updated: 2024-08-07T14:09:26.583Z
Status : Analyzed
Published: 2024-08-01T15:15:12.587
Modified: 2024-08-23T14:35:13.670
Link: CVE-2024-39832
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA