PT-2024-28688 · Mattermost · Mattermost

Juho Forsén

·

Published

2024-07-03

·

Updated

2024-07-05

·

CVE-2024-39830

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Mattermost versions 9.5.x through 9.5.5 Mattermost versions 9.6.x through 9.6.2 Mattermost versions 9.7.x through 9.7.4 Mattermost versions 9.8.x through 9.8.0
Description The issue arises when shared channels are enabled, and the software fails to use constant time comparison for remote cluster tokens. This allows an attacker to potentially retrieve the remote cluster token via a timing attack during remote cluster token comparison.
Recommendations For Mattermost versions 9.5.x through 9.5.5, update to a version that uses constant time comparison for remote cluster tokens. For Mattermost versions 9.6.x through 9.6.2, update to a version that uses constant time comparison for remote cluster tokens. For Mattermost versions 9.7.x through 9.7.4, update to a version that uses constant time comparison for remote cluster tokens. For Mattermost versions 9.8.x through 9.8.0, update to a version that uses constant time comparison for remote cluster tokens.

Fix

Improper Authentication

Side Channel Attack

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-39830

Affected Products

Mattermost