PT-2024-28470 · Mattermost · Mattermost

Juho Forsén

·

Published

2024-07-03

·

Updated

2024-07-05

·

CVE-2024-39361

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Mattermost versions 9.5.x through 9.5.5 Mattermost versions 9.6.x through 9.6.2 Mattermost versions 9.7.x through 9.7.4 Mattermost version 9.8.0
Description The issue allows attackers to specify both a remoteId and the post ID, resulting in creating a post with a user-defined post ID. This can cause broken functionality in the channel or thread with user-defined posts.
Recommendations For Mattermost versions 9.5.x through 9.5.5, update to a version that prevents users from specifying a RemoteId for their posts. For Mattermost versions 9.6.x through 9.6.2, update to a version that prevents users from specifying a RemoteId for their posts. For Mattermost versions 9.7.x through 9.7.4, update to a version that prevents users from specifying a RemoteId for their posts. For Mattermost version 9.8.0, update to a version that prevents users from specifying a RemoteId for their posts.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2024-39361

Affected Products

Mattermost