Description
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to disallow users to set their own remote username, when shared channels were enabled, which allows a user on a remote to set their remote username prop to an arbitrary string, which would be then synced to the local server as long as the user hadn't been synced before.
Published: 2024-08-01
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Update Mattermost to versions 9.10.0, 9.9.1, 9.5.7, 9.7.6, 9.8.2 or higher.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-2663 Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to disallow users to set their own remote username, when shared channels were enabled, which allows a user on a remote to set their remote username prop to an arbitrary string, which would be then synced to the local server as long as the user hadn't been synced before.
Github GHSA Github GHSA GHSA-vg6q-84p8-qvqh Mattermost allows a user on a remote to set their remote username prop to an arbitrary string
References
History

Wed, 04 Sep 2024 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost
Mattermost mattermost Server
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
cpe:2.3:a:mattermost:mattermost_server:9.9.0:*:*:*:*:*:*:*
Vendors & Products Mattermost
Mattermost mattermost Server

Subscriptions

Mattermost Mattermost Server
cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2024-08-01T18:04:42.351Z

Reserved: 2024-07-23T18:35:14.805Z

Link: CVE-2024-39839

cve-icon Vulnrichment

Updated: 2024-08-01T18:04:36.748Z

cve-icon NVD

Status : Analyzed

Published: 2024-08-01T15:15:12.993

Modified: 2024-09-04T17:34:06.817

Link: CVE-2024-39839

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses