PT-2024-28415 · Mattermost · Mattermost

Juho Forsén

·

Published

2024-08-01

·

Updated

2024-08-23

·

CVE-2024-39274

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions Mattermost versions 9.5.x through 9.5.6 Mattermost versions 9.7.x through 9.7.5 Mattermost versions 9.8.x through 9.8.1 Mattermost versions 9.9.x through 9.9.0
Description The issue arises from the failure to properly validate that the channel coming from the sync message is a shared channel when shared channels are enabled. This allows a malicious remote to add users to arbitrary teams and channels.
Recommendations For Mattermost versions 9.5.x through 9.5.6, update to a version later than 9.5.6 to resolve the issue. For Mattermost versions 9.7.x through 9.7.5, update to a version later than 9.7.5 to resolve the issue. For Mattermost versions 9.8.x through 9.8.1, update to a version later than 9.8.1 to resolve the issue. For Mattermost versions 9.9.x through 9.9.0, update to a version later than 9.9.0 to resolve the issue.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2024-39274
GHSA-CMC8-222C-VQP9
GO-2024-3028

Affected Products

Mattermost