PT-2024-26936 · Mattermost · Mattermost

Juho Forsén

·

Published

2024-07-03

·

Updated

2024-07-05

·

CVE-2024-36257

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Mattermost versions 9.5.x through 9.5.5 Mattermost version 9.8.0
Description The issue arises when Mattermost is used with shared channels and multiple remote servers are connected. In such cases, the system fails to verify that the remote server requesting a profile picture update for a user is the same server where the user is locally hosted. This oversight allows a malicious remote server to alter the profile images of users belonging to another remote server that is connected to it.
Recommendations For Mattermost versions 9.5.x through 9.5.5, update to a version later than 9.5.5 to resolve the issue. For Mattermost version 9.8.0, update to a version later than 9.8.0 to resolve the issue. As a temporary workaround, consider restricting access to profile picture updates for users from remote servers until a patch is available.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2024-36257

Affected Products

Mattermost