Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to disallow users to set their own remote username, when shared channels were enabled, which allows a user on a remote to set their remote username prop to an arbitrary string, which would be then synced to the local server as long as the user hadn't been synced before.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://mattermost.com/security-updates |
History
Wed, 04 Sep 2024 18:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Mattermost
Mattermost mattermost Server |
|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* cpe:2.3:a:mattermost:mattermost_server:9.9.0:*:*:*:*:*:*:* |
|
Vendors & Products |
Mattermost
Mattermost mattermost Server |
MITRE
Status: PUBLISHED
Assigner: Mattermost
Published: 2024-08-01T14:05:07.339Z
Updated: 2024-08-01T18:04:42.351Z
Reserved: 2024-07-23T18:35:14.805Z
Link: CVE-2024-39839
Vulnrichment
Updated: 2024-08-01T18:04:36.748Z
NVD
Status : Analyzed
Published: 2024-08-01T15:15:12.993
Modified: 2024-09-04T17:34:06.817
Link: CVE-2024-39839
Redhat
No data.