Description
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6 fail to properly restrict channel creation which allows a malicious remote to create arbitrary channels, when shared channels were enabled.
No analysis available yet.
Remediation
Vendor Solution
Update Mattermost to versions 9.10.0, 9.9.1, 9.5.7 or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2667 | Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6 fail to properly restrict channel creation which allows a malicious remote to create arbitrary channels, when shared channels were enabled. |
Github GHSA |
GHSA-vvpg-55p7-5h8w | Mattermost did not properly restrict channel creation |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
Wed, 04 Sep 2024 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost
Mattermost mattermost Server |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* cpe:2.3:a:mattermost:mattermost_server:9.9.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Mattermost
Mattermost mattermost Server |
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-08-01T20:47:51.530Z
Reserved: 2024-07-23T17:55:45.342Z
Link: CVE-2024-39837
Updated: 2024-08-01T20:47:47.740Z
Status : Analyzed
Published: 2024-08-01T15:15:12.790
Modified: 2024-09-04T17:38:42.297
Link: CVE-2024-39837
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA