PT-2024-27027 · Mattermost · Mattermost

Juho Forsén

·

Published

2024-08-01

·

Updated

2024-08-23

·

CVE-2024-36492

CVSS v3.1

7.4

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Mattermost versions 9.5.x through 9.5.6 Mattermost versions 9.7.x through 9.7.5 Mattermost versions 9.8.x through 9.8.1 Mattermost versions 9.9.x through 9.9.0
Description The issue allows a malicious remote user to overwrite an existing local user when syncing users in shared channels, due to the failure to disallow the modification of local users. This is related to the syncing of users in shared channels.
Recommendations For Mattermost versions 9.5.x through 9.5.6, update to a version later than 9.5.6 to resolve the issue. For Mattermost versions 9.7.x through 9.7.5, update to a version later than 9.7.5 to resolve the issue. For Mattermost versions 9.8.x through 9.8.1, update to a version later than 9.8.1 to resolve the issue. For Mattermost versions 9.9.x through 9.9.0, update to a version later than 9.9.0 to resolve the issue.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2024-36492
GHSA-56MC-F9W7-2WXQ
GO-2024-3025

Affected Products

Mattermost