Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to ensure that remote/synthetic users cannot create sessions or reset passwords, which allows the munged email addresses, created by shared channels, to be used to receive email notifications and to reset passwords, when they are valid, functional emails.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://mattermost.com/security-updates |
History
Fri, 23 Aug 2024 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Mattermost
Mattermost mattermost |
|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*:* | |
Vendors & Products |
Mattermost
Mattermost mattermost |
Thu, 22 Aug 2024 17:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 22 Aug 2024 06:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to ensure that remote/synthetic users cannot create sessions or reset passwords, which allows the munged email addresses, created by shared channels, to be used to receive email notifications and to reset passwords, when they are valid, functional emails. | |
Title | Munged email address used for password resets and notifications | |
Weaknesses | CWE-693 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Mattermost
Published: 2024-08-22T06:27:09.829Z
Updated: 2024-08-22T16:39:21.881Z
Reserved: 2024-08-20T16:09:35.902Z
Link: CVE-2024-39836
Vulnrichment
Updated: 2024-08-22T16:39:19.010Z
NVD
Status : Analyzed
Published: 2024-08-22T07:15:03.960
Modified: 2024-08-23T16:16:18.757
Link: CVE-2024-39836
Redhat
No data.