Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to disallow users to set their own remote username, when shared channels were enabled, which allows a user on a remote to set their remote username prop to an arbitrary string, which would be then synced to the local server as long as the user hadn't been synced before.
References
History

Wed, 04 Sep 2024 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost
Mattermost mattermost Server
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
cpe:2.3:a:mattermost:mattermost_server:9.9.0:*:*:*:*:*:*:*
Vendors & Products Mattermost
Mattermost mattermost Server

cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published: 2024-08-01T14:05:07.339Z

Updated: 2024-08-01T18:04:42.351Z

Reserved: 2024-07-23T18:35:14.805Z

Link: CVE-2024-39839

cve-icon Vulnrichment

Updated: 2024-08-01T18:04:36.748Z

cve-icon NVD

Status : Analyzed

Published: 2024-08-01T15:15:12.993

Modified: 2024-09-04T17:34:06.817

Link: CVE-2024-39839

cve-icon Redhat

No data.