Description
Mattermost versions 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2, 9.5.x <= 9.5.5 fail to prevent specifying a RemoteId when creating a new user which allows an attacker to specify both a remoteId and the user ID, resulting in creating a user with a user-defined user ID. This can cause some broken functionality in User Management such administrative actions against the user not working.
No analysis available yet.
Remediation
Vendor Solution
Update Mattermost to versions 9.9.0, 9.8.1, 9.7.5, 9.6.3, 9.5.6 or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-47531 | Mattermost versions 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2, 9.5.x <= 9.5.5 fail to prevent specifying a RemoteId when creating a new user which allows an attacker to specify both a remoteId and the user ID, resulting in creating a user with a user-defined user ID. This can cause some broken functionality in User Management such administrative actions against the user not working. |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
No history.
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-08-01T21:41:03.285Z
Reserved: 2024-07-01T12:15:48.662Z
Link: CVE-2024-6428
Updated: 2024-08-01T21:41:03.285Z
Status : Modified
Published: 2024-07-03T09:15:08.013
Modified: 2024-11-21T09:49:38.313
Link: CVE-2024-6428
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD