Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2555 | Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to ensure that remote/synthetic users cannot create sessions or reset passwords, which allows the munged email addresses, created by shared channels, to be used to receive email notifications and to reset passwords, when they are valid, functional emails. |
Github GHSA |
GHSA-c6vp-jjgv-38wj | Mattermost allows remote/synthetic users to create sessions, reset passwords |
Solution
Update Mattermost to versions 9.11.0, 9.9.2, 9.5.8, 9.10.1, 9.8.3 or higher.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
Fri, 23 Aug 2024 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost
Mattermost mattermost |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mattermost
Mattermost mattermost |
Thu, 22 Aug 2024 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 22 Aug 2024 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to ensure that remote/synthetic users cannot create sessions or reset passwords, which allows the munged email addresses, created by shared channels, to be used to receive email notifications and to reset passwords, when they are valid, functional emails. | |
| Title | Munged email address used for password resets and notifications | |
| Weaknesses | CWE-693 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-08-22T16:39:21.881Z
Reserved: 2024-08-20T16:09:35.902Z
Link: CVE-2024-39836
Updated: 2024-08-22T16:39:19.010Z
Status : Analyzed
Published: 2024-08-22T07:15:03.960
Modified: 2024-08-23T16:16:18.757
Link: CVE-2024-39836
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA